starting build "cf4dbd25-4109-49dc-a505-d4c898a3b8e1" FETCHSOURCE BUILD Starting Step #0 Step #0: Already have image (with digest): gcr.io/cloud-builders/git Step #0: Cloning into 'oss-fuzz'... Finished Step #0 Starting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb" Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Already have image (with digest): gcr.io/cloud-builders/docker Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Sending build context to Docker daemon 6.656kB Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Step 1/5 : FROM gcr.io/oss-fuzz-base/base-builder Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": latest: Pulling from oss-fuzz-base/base-builder Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": b549f31133a9: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 0080ba77da4f: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ba15b34d2160: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": e04266c6405f: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 797a6452a81e: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c1981600b8ed: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9423b9fd2cfc: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 6737144a8851: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": a3f978eb4fb6: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 967f1a7ca65b: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 17c9041f18bc: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 929348ee61ec: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ecac57c52be5: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c2162772e245: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 932b4ea0b424: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 65d72fefd09b: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": d58a1ec768e4: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ad7f3404b9ff: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c89cf94d8da5: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": d80b495ff003: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": bcde0b24214c: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 2630b08c5260: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9f48b30a8679: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 82e7030f0fb5: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 5345e7fac9a3: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9f58272f4333: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9b9cc0234933: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 33be286798e3: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 0341c3015714: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 6f827bf882ab: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": a23d0c0db0f8: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 7d6daf7f4ec0: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 59e65fbb5b03: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9423b9fd2cfc: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": da3daa385d8a: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": e122ad1f2964: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 6737144a8851: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c9f9d5d44d5d: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 37bce15499bd: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": d58a1ec768e4: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": fbb27bb2508b: Pulling fs layer Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 82e7030f0fb5: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 967f1a7ca65b: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ad7f3404b9ff: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 17c9041f18bc: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c2162772e245: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": e122ad1f2964: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c9f9d5d44d5d: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ecac57c52be5: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 59e65fbb5b03: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 932b4ea0b424: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 6f827bf882ab: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 65d72fefd09b: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9f48b30a8679: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": fbb27bb2508b: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c89cf94d8da5: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 2630b08c5260: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": d80b495ff003: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9b9cc0234933: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 33be286798e3: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 5345e7fac9a3: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 0341c3015714: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 7d6daf7f4ec0: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9f58272f4333: Waiting Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ba15b34d2160: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ba15b34d2160: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 797a6452a81e: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 6737144a8851: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9423b9fd2cfc: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": b549f31133a9: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": b549f31133a9: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": e04266c6405f: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": e04266c6405f: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 17c9041f18bc: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 17c9041f18bc: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 929348ee61ec: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 929348ee61ec: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ecac57c52be5: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ecac57c52be5: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 0080ba77da4f: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 0080ba77da4f: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c2162772e245: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c2162772e245: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 65d72fefd09b: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 65d72fefd09b: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 932b4ea0b424: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 932b4ea0b424: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 967f1a7ca65b: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 967f1a7ca65b: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c89cf94d8da5: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": d58a1ec768e4: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": d58a1ec768e4: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ad7f3404b9ff: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ad7f3404b9ff: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": bcde0b24214c: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": bcde0b24214c: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 2630b08c5260: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": b549f31133a9: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": d80b495ff003: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": d80b495ff003: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 82e7030f0fb5: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 5345e7fac9a3: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 5345e7fac9a3: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9f48b30a8679: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9f48b30a8679: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9f58272f4333: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9b9cc0234933: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 33be286798e3: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 33be286798e3: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": a3f978eb4fb6: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": a3f978eb4fb6: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 0341c3015714: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 0341c3015714: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 6f827bf882ab: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 6f827bf882ab: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": a23d0c0db0f8: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": a23d0c0db0f8: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 7d6daf7f4ec0: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 59e65fbb5b03: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 59e65fbb5b03: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": da3daa385d8a: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": da3daa385d8a: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": e122ad1f2964: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": e122ad1f2964: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c9f9d5d44d5d: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c9f9d5d44d5d: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": fbb27bb2508b: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": fbb27bb2508b: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 37bce15499bd: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 37bce15499bd: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c1981600b8ed: Verifying Checksum Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c1981600b8ed: Download complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 0080ba77da4f: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ba15b34d2160: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": e04266c6405f: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 797a6452a81e: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c1981600b8ed: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9423b9fd2cfc: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 6737144a8851: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": a3f978eb4fb6: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 967f1a7ca65b: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 17c9041f18bc: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 929348ee61ec: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ecac57c52be5: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c2162772e245: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 932b4ea0b424: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 65d72fefd09b: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": d58a1ec768e4: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ad7f3404b9ff: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c89cf94d8da5: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": d80b495ff003: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": bcde0b24214c: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 2630b08c5260: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9f48b30a8679: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 82e7030f0fb5: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 5345e7fac9a3: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9f58272f4333: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 9b9cc0234933: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 33be286798e3: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 0341c3015714: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 6f827bf882ab: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": a23d0c0db0f8: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 7d6daf7f4ec0: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 59e65fbb5b03: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": da3daa385d8a: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": e122ad1f2964: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": c9f9d5d44d5d: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": 37bce15499bd: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": fbb27bb2508b: Pull complete Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Digest: sha256:b38b34172cfa570f6c2b87ce6d7204843c1d4c3cd2cb7a5c83d6bb1a8ea93be5 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Status: Downloaded newer image for gcr.io/oss-fuzz-base/base-builder:latest Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ---> 393977acddb4 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Step 2/5 : RUN pip3 install meson ninja Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ---> Running in d5c1b1d61a33 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Collecting meson Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Downloading meson-1.11.2-py3-none-any.whl.metadata (1.8 kB) Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Collecting ninja Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Downloading ninja-1.13.0-py3-none-manylinux2014_x86_64.manylinux_2_17_x86_64.whl.metadata (5.1 kB) Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Downloading meson-1.11.2-py3-none-any.whl (1.1 MB) Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 1.1/1.1 MB 28.9 MB/s 0:00:00 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Downloading ninja-1.13.0-py3-none-manylinux2014_x86_64.manylinux_2_17_x86_64.whl (180 kB) Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Installing collected packages: ninja, meson Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Successfully installed meson-1.11.2 ninja-1.13.0 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": WARNING: Running pip as the 'root' user can result in broken permissions and conflicting behaviour with the system package manager, possibly rendering your system unusable. It is recommended to use a virtual environment instead: https://pip.pypa.io/warnings/venv. Use the --root-user-action option if you know what you are doing and want to suppress this warning. Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Removing intermediate container d5c1b1d61a33 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ---> f1908b8ad759 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Step 3/5 : RUN git clone --depth 1 https://github.com/syoyo/tinygltf.git Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ---> Running in 2e965fb4b4dc Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Cloning into 'tinygltf'... Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Removing intermediate container 2e965fb4b4dc Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ---> 13a7a8b90806 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Step 4/5 : WORKDIR $SRC/tinygltf Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ---> Running in ccf3b518db0c Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Removing intermediate container ccf3b518db0c Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ---> 1b02d11232b0 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Step 5/5 : COPY run_tests.sh build.sh $SRC/ Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": ---> f488d1932e97 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Successfully built f488d1932e97 Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Successfully tagged gcr.io/oss-fuzz/tinygltf:latest Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb": Successfully tagged us-central1-docker.pkg.dev/oss-fuzz/unsafe/tinygltf:latest Finished Step #1 - "build-7165d30b-12cd-40c7-8538-70c4d92ff4fb" Starting Step #2 - "srcmap" Step #2 - "srcmap": Already have image: gcr.io/oss-fuzz/tinygltf Step #2 - "srcmap": ++ tempfile Step #2 - "srcmap": + SRCMAP=/tmp/fileZ9OvlO Step #2 - "srcmap": + echo '{}' Step #2 - "srcmap": + PATHS_TO_SCAN=/src Step #2 - "srcmap": + [[ c++ == \g\o ]] Step #2 - "srcmap": ++ find /src -name .git -type d Step #2 - "srcmap": + for DOT_GIT_DIR in $(find $PATHS_TO_SCAN -name ".git" -type d) Step #2 - "srcmap": ++ dirname /src/tinygltf/.git Step #2 - "srcmap": + GIT_DIR=/src/tinygltf Step #2 - "srcmap": + cd /src/tinygltf Step #2 - "srcmap": ++ git config --get remote.origin.url Step #2 - "srcmap": + GIT_URL=https://github.com/syoyo/tinygltf.git Step #2 - "srcmap": ++ git rev-parse HEAD Step #2 - "srcmap": + GIT_REV=a434ee02066c2d9b62a3504876aed38e6e399fe0 Step #2 - "srcmap": + jq_inplace /tmp/fileZ9OvlO '."/src/tinygltf" = { type: "git", url: "https://github.com/syoyo/tinygltf.git", rev: "a434ee02066c2d9b62a3504876aed38e6e399fe0" }' Step #2 - "srcmap": ++ tempfile Step #2 - "srcmap": + F=/tmp/fileAd97Ha Step #2 - "srcmap": + cat /tmp/fileZ9OvlO Step #2 - "srcmap": + jq '."/src/tinygltf" = { type: "git", url: "https://github.com/syoyo/tinygltf.git", rev: "a434ee02066c2d9b62a3504876aed38e6e399fe0" }' Step #2 - "srcmap": + mv /tmp/fileAd97Ha /tmp/fileZ9OvlO Step #2 - "srcmap": ++ find /src -name .svn -type d Step #2 - "srcmap": ++ find /src -name .hg -type d Step #2 - "srcmap": + '[' '' '!=' '' ']' Step #2 - "srcmap": + cat /tmp/fileZ9OvlO Step #2 - "srcmap": + rm /tmp/fileZ9OvlO Step #2 - "srcmap": { Step #2 - "srcmap": "/src/tinygltf": { Step #2 - "srcmap": "type": "git", Step #2 - "srcmap": "url": "https://github.com/syoyo/tinygltf.git", Step #2 - "srcmap": "rev": "a434ee02066c2d9b62a3504876aed38e6e399fe0" Step #2 - "srcmap": } Step #2 - "srcmap": } Finished Step #2 - "srcmap" Starting Step #3 - "compile-libfuzzer-coverage-x86_64" Step #3 - "compile-libfuzzer-coverage-x86_64": Already have image (with digest): gcr.io/cloud-builders/docker Step #3 - "compile-libfuzzer-coverage-x86_64": --------------------------------------------------------------- Step #3 - "compile-libfuzzer-coverage-x86_64": vm.mmap_rnd_bits = 28 Step #3 - "compile-libfuzzer-coverage-x86_64": Compiling libFuzzer to /usr/lib/libFuzzingEngine.a... done. Step #3 - "compile-libfuzzer-coverage-x86_64": --------------------------------------------------------------- Step #3 - "compile-libfuzzer-coverage-x86_64": CC=clang Step #3 - "compile-libfuzzer-coverage-x86_64": CXX=clang++ Step #3 - "compile-libfuzzer-coverage-x86_64": CFLAGS=-O1 -fno-omit-frame-pointer -gline-tables-only -Wno-error=incompatible-function-pointer-types -Wno-error=int-conversion -Wno-error=deprecated-declarations -Wno-error=implicit-function-declaration -Wno-error=implicit-int -Wno-error=unknown-warning-option -Wno-error=vla-cxx-extension -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION -fprofile-instr-generate -fcoverage-mapping -pthread -Wl,--no-as-needed -Wl,-ldl -Wl,-lm -Wno-unused-command-line-argument Step #3 - "compile-libfuzzer-coverage-x86_64": CXXFLAGS=-O1 -fno-omit-frame-pointer -gline-tables-only -Wno-error=incompatible-function-pointer-types -Wno-error=int-conversion -Wno-error=deprecated-declarations -Wno-error=implicit-function-declaration -Wno-error=implicit-int -Wno-error=unknown-warning-option -Wno-error=vla-cxx-extension -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION -fprofile-instr-generate -fcoverage-mapping -pthread -Wl,--no-as-needed -Wl,-ldl -Wl,-lm -Wno-unused-command-line-argument -stdlib=libc++ Step #3 - "compile-libfuzzer-coverage-x86_64": RUSTFLAGS=--cfg fuzzing -Cdebuginfo=1 -Cforce-frame-pointers -Cinstrument-coverage -C link-arg=-lc++ Step #3 - "compile-libfuzzer-coverage-x86_64": --------------------------------------------------------------- Step #3 - "compile-libfuzzer-coverage-x86_64": + cd tests/fuzzer/ Step #3 - "compile-libfuzzer-coverage-x86_64": + meson build Step #3 - "compile-libfuzzer-coverage-x86_64": The Meson build system Step #3 - "compile-libfuzzer-coverage-x86_64": Version: 1.11.2 Step #3 - "compile-libfuzzer-coverage-x86_64": Source dir: /src/tinygltf/tests/fuzzer Step #3 - "compile-libfuzzer-coverage-x86_64": Build dir: /src/tinygltf/tests/fuzzer/build Step #3 - "compile-libfuzzer-coverage-x86_64": Build type: native build Step #3 - "compile-libfuzzer-coverage-x86_64": Project name: fuzz_tinygltf Step #3 - "compile-libfuzzer-coverage-x86_64": Project version: undefined Step #3 - "compile-libfuzzer-coverage-x86_64": C++ compiler for the host machine: clang++ (clang 22.0.0 "clang version 22.0.0git (https://github.com/llvm/llvm-project.git cb2f0d0a5f14c183e7182aba0f0e54a518de9e3f)") Step #3 - "compile-libfuzzer-coverage-x86_64": C++ linker for the host machine: clang++ ld.bfd 2.34 Step #3 - "compile-libfuzzer-coverage-x86_64": Host machine cpu family: x86_64 Step #3 - "compile-libfuzzer-coverage-x86_64": Host machine cpu: x86_64 Step #3 - "compile-libfuzzer-coverage-x86_64": Build targets in project: 2 Step #3 - "compile-libfuzzer-coverage-x86_64": Step #3 - "compile-libfuzzer-coverage-x86_64": Found ninja-1.13.0.git.kitware.jobserver-pipe-1 at /usr/local/bin/ninja Step #3 - "compile-libfuzzer-coverage-x86_64": WARNING: Running the setup command as `meson [options]` instead of `meson setup [options]` is ambiguous and deprecated. Step #3 - "compile-libfuzzer-coverage-x86_64": + cd build Step #3 - "compile-libfuzzer-coverage-x86_64": ++ nproc Step #3 - "compile-libfuzzer-coverage-x86_64": + ninja -j32 Step #3 - "compile-libfuzzer-coverage-x86_64": [0/4] Compiling C++ object fuzz_gltf.p/fuzz_gltf.cc.o [0/4] Compiling C++ object fuzz_gltf_customjson.p/fuzz_gltf_customjson.cc.o [1/4] Compiling C++ object fuzz_gltf_customjson.p/fuzz_gltf_customjson.cc.o [1/4] Linking target fuzz_gltf_customjson [2/4] Linking target fuzz_gltf_customjson [3/4] Compiling C++ object fuzz_gltf.p/fuzz_gltf.cc.o Step #3 - "compile-libfuzzer-coverage-x86_64": In file included from ../fuzz_gltf.cc:10: Step #3 - "compile-libfuzzer-coverage-x86_64": In file included from ../../../tiny_gltf.h:1719: Step #3 - "compile-libfuzzer-coverage-x86_64": ../../../json.hpp:26551:35: warning: identifier '_json' preceded by whitespace in a literal operator declaration is deprecated [-Wdeprecated-literal-operator] Step #3 - "compile-libfuzzer-coverage-x86_64": 26551 | inline nlohmann::json operator "" _json(const char* s, std::size_t n) Step #3 - "compile-libfuzzer-coverage-x86_64": |  ~~~~~~~~~~~~^~~~~ Step #3 - "compile-libfuzzer-coverage-x86_64":  |  operator""_json Step #3 - "compile-libfuzzer-coverage-x86_64": ../../../json.hpp:26570:49: warning: identifier '_json_pointer' preceded by whitespace in a literal operator declaration is deprecated [-Wdeprecated-literal-operator] Step #3 - "compile-libfuzzer-coverage-x86_64": 26570 | inline nlohmann::json::json_pointer operator "" _json_pointer(const char* s, std::size_t n) Step #3 - "compile-libfuzzer-coverage-x86_64": |  ~~~~~~~~~~~~^~~~~~~~~~~~~ Step #3 - "compile-libfuzzer-coverage-x86_64":  |  operator""_json_pointer Step #3 - "compile-libfuzzer-coverage-x86_64": 2 warnings generated. Step #3 - "compile-libfuzzer-coverage-x86_64": [3/4] Linking target fuzz_gltf [4/4] Linking target fuzz_gltf Step #3 - "compile-libfuzzer-coverage-x86_64": + cp fuzz_gltf_customjson fuzz_gltf /workspace/out/libfuzzer-coverage-x86_64/ Step #3 - "compile-libfuzzer-coverage-x86_64": + cd /src/tinygltf Step #3 - "compile-libfuzzer-coverage-x86_64": + cmake . Step #3 - "compile-libfuzzer-coverage-x86_64": -- The C compiler identification is Clang 22.0.0 Step #3 - "compile-libfuzzer-coverage-x86_64": -- The CXX compiler identification is Clang 22.0.0 Step #3 - "compile-libfuzzer-coverage-x86_64": -- Detecting C compiler ABI info Step #3 - "compile-libfuzzer-coverage-x86_64": -- Detecting C compiler ABI info - done Step #3 - "compile-libfuzzer-coverage-x86_64": -- Check for working C compiler: /usr/local/bin/clang - skipped Step #3 - "compile-libfuzzer-coverage-x86_64": -- Detecting C compile features Step #3 - "compile-libfuzzer-coverage-x86_64": -- Detecting C compile features - done Step #3 - "compile-libfuzzer-coverage-x86_64": -- Detecting CXX compiler ABI info Step #3 - "compile-libfuzzer-coverage-x86_64": -- Detecting CXX compiler ABI info - done Step #3 - "compile-libfuzzer-coverage-x86_64": -- Check for working CXX compiler: /usr/local/bin/clang++ - skipped Step #3 - "compile-libfuzzer-coverage-x86_64": -- Detecting CXX compile features Step #3 - "compile-libfuzzer-coverage-x86_64": -- Detecting CXX compile features - done Step #3 - "compile-libfuzzer-coverage-x86_64": -- Configuring done (0.4s) Step #3 - "compile-libfuzzer-coverage-x86_64": -- Generating done (0.0s) Step #3 - "compile-libfuzzer-coverage-x86_64": -- Build files have been written to: /src/tinygltf Step #3 - "compile-libfuzzer-coverage-x86_64": + make -C tests Step #3 - "compile-libfuzzer-coverage-x86_64": make: Entering directory '/src/tinygltf/tests' Step #3 - "compile-libfuzzer-coverage-x86_64": clang -I../ -std=c11 -g -O0 -DTINYGLTF3_ENABLE_FS -o tester_v3_c tester_v3_c.c ../tiny_gltf_v3.c Step #3 - "compile-libfuzzer-coverage-x86_64": clang -I../ -std=c11 -g -O0 -DTINYGLTF3_ENABLE_FS -o tester_v3_c_v1port tester_v3_c_v1port.c ../tiny_gltf_v3.c Step #3 - "compile-libfuzzer-coverage-x86_64": clang -I../ -std=c11 -g -O0 -o tester_v3_json_c tester_v3_json_c.c Step #3 - "compile-libfuzzer-coverage-x86_64": clang -I../ -std=c11 -ffreestanding -g -O0 -o tester_v3_freestanding tester_v3_freestanding.c Step #3 - "compile-libfuzzer-coverage-x86_64": clang++ -I../ -std=c++11 -g -O0 -o tester tester.cc Step #3 - "compile-libfuzzer-coverage-x86_64": In file included from tester.cc:4: Step #3 - "compile-libfuzzer-coverage-x86_64": In file included from ../tiny_gltf.h:1719: Step #3 - "compile-libfuzzer-coverage-x86_64": ../json.hpp:26551:35: warning: identifier '_json' preceded by whitespace in a literal operator declaration is deprecated [-Wdeprecated-literal-operator] Step #3 - "compile-libfuzzer-coverage-x86_64": 26551 | inline nlohmann::json operator "" _json(const char* s, std::size_t n) Step #3 - "compile-libfuzzer-coverage-x86_64": |  ~~~~~~~~~~~~^~~~~ Step #3 - "compile-libfuzzer-coverage-x86_64":  |  operator""_json Step #3 - "compile-libfuzzer-coverage-x86_64": ../json.hpp:26570:49: warning: identifier '_json_pointer' preceded by whitespace in a literal operator declaration is deprecated [-Wdeprecated-literal-operator] Step #3 - "compile-libfuzzer-coverage-x86_64": 26570 | inline nlohmann::json::json_pointer operator "" _json_pointer(const char* s, std::size_t n) Step #3 - "compile-libfuzzer-coverage-x86_64": |  ~~~~~~~~~~~~^~~~~~~~~~~~~ Step #3 - "compile-libfuzzer-coverage-x86_64":  |  operator""_json_pointer Step #3 - "compile-libfuzzer-coverage-x86_64": 2 warnings generated. Step #3 - "compile-libfuzzer-coverage-x86_64": clang++ -DTINYGLTF_NOEXCEPTION -I../ -std=c++11 -g -O0 -o tester_noexcept tester.cc Step #3 - "compile-libfuzzer-coverage-x86_64": In file included from tester.cc:4: Step #3 - "compile-libfuzzer-coverage-x86_64": In file included from ../tiny_gltf.h:1719: Step #3 - "compile-libfuzzer-coverage-x86_64": ../json.hpp:26551:35: warning: identifier '_json' preceded by whitespace in a literal operator declaration is deprecated [-Wdeprecated-literal-operator] Step #3 - "compile-libfuzzer-coverage-x86_64": 26551 | inline nlohmann::json operator "" _json(const char* s, std::size_t n) Step #3 - "compile-libfuzzer-coverage-x86_64": |  ~~~~~~~~~~~~^~~~~ Step #3 - "compile-libfuzzer-coverage-x86_64":  |  operator""_json Step #3 - "compile-libfuzzer-coverage-x86_64": ../json.hpp:26570:49: warning: identifier '_json_pointer' preceded by whitespace in a literal operator declaration is deprecated [-Wdeprecated-literal-operator] Step #3 - "compile-libfuzzer-coverage-x86_64": 26570 | inline nlohmann::json::json_pointer operator "" _json_pointer(const char* s, std::size_t n) Step #3 - "compile-libfuzzer-coverage-x86_64": |  ~~~~~~~~~~~~^~~~~~~~~~~~~ Step #3 - "compile-libfuzzer-coverage-x86_64":  |  operator""_json_pointer Step #3 - "compile-libfuzzer-coverage-x86_64": 2 warnings generated. Step #3 - "compile-libfuzzer-coverage-x86_64": clang++ -DTINYGLTF_USE_CUSTOM_JSON -I../ -std=c++11 -g -O0 -o tester_intensive_customjson tester_intensive_customjson.cc Step #3 - "compile-libfuzzer-coverage-x86_64": make: Leaving directory '/src/tinygltf/tests' Finished Step #3 - "compile-libfuzzer-coverage-x86_64" Starting Step #4 Step #4: Pulling image: gcr.io/oss-fuzz-base/base-runner Step #4: Using default tag: latest Step #4: latest: Pulling from oss-fuzz-base/base-runner Step #4: b549f31133a9: Already exists Step #4: 0080ba77da4f: Already exists Step #4: ba15b34d2160: Already exists Step #4: 755e96391592: Pulling fs layer Step #4: cc42a684cc86: Pulling fs layer Step #4: cf2e8929c5d2: Pulling fs layer Step #4: c8181fa11e67: Pulling fs layer Step #4: 27c36f21ce6c: Pulling fs layer Step #4: 5054ea471fa9: Pulling fs layer Step #4: d6250e629dd4: Pulling fs layer Step #4: 27e64bf5af43: Pulling fs layer Step #4: c5ff56ffb0e4: Pulling fs layer Step #4: 8fb0b5be246f: Pulling fs layer Step #4: 476d1bd54eba: Pulling fs layer Step #4: b65bb9c2b3ee: Pulling fs layer Step #4: 7f20d5b45eae: Pulling fs layer Step #4: ed78c72f0edc: Pulling fs layer Step #4: 28420101279a: Pulling fs layer Step #4: 1e91a5bf9d06: Pulling fs layer Step #4: c7997b4917ac: Pulling fs layer Step #4: 53dc9df53f1f: Pulling fs layer Step #4: dfd94ecde904: Pulling fs layer Step #4: bdd9722b34e4: Pulling fs layer Step #4: 3b47b475d1e5: Pulling fs layer Step #4: e9487f394bbf: Pulling fs layer Step #4: fdd56c8ed1fe: Pulling fs layer Step #4: b9bc039bd211: Pulling fs layer Step #4: c01e504f77ea: Pulling fs layer Step #4: 27e64bf5af43: Waiting Step #4: c5ff56ffb0e4: Waiting Step #4: 1e91a5bf9d06: Waiting Step #4: 8fb0b5be246f: Waiting Step #4: 7f20d5b45eae: Waiting Step #4: 476d1bd54eba: Waiting Step #4: c7997b4917ac: Waiting Step #4: ed78c72f0edc: Waiting Step #4: 28420101279a: Waiting Step #4: b65bb9c2b3ee: Waiting Step #4: 53dc9df53f1f: Waiting Step #4: dfd94ecde904: Waiting Step #4: fdd56c8ed1fe: Waiting Step #4: b9bc039bd211: Waiting Step #4: bdd9722b34e4: Waiting Step #4: e9487f394bbf: Waiting Step #4: d6250e629dd4: Waiting Step #4: c01e504f77ea: Waiting Step #4: cf2e8929c5d2: Verifying Checksum Step #4: cf2e8929c5d2: Download complete Step #4: 27c36f21ce6c: Verifying Checksum Step #4: 27c36f21ce6c: Download complete Step #4: 755e96391592: Verifying Checksum Step #4: cc42a684cc86: Verifying Checksum Step #4: cc42a684cc86: Download complete Step #4: c8181fa11e67: Verifying Checksum Step #4: c8181fa11e67: Download complete Step #4: d6250e629dd4: Download complete Step #4: 27e64bf5af43: Verifying Checksum Step #4: 27e64bf5af43: Download complete Step #4: 755e96391592: Pull complete Step #4: c5ff56ffb0e4: Verifying Checksum Step #4: c5ff56ffb0e4: Download complete Step #4: b65bb9c2b3ee: Verifying Checksum Step #4: b65bb9c2b3ee: Download complete Step #4: 7f20d5b45eae: Download complete Step #4: 476d1bd54eba: Verifying Checksum Step #4: 476d1bd54eba: Download complete Step #4: 28420101279a: Verifying Checksum Step #4: 28420101279a: Download complete Step #4: 5054ea471fa9: Verifying Checksum Step #4: 5054ea471fa9: Download complete Step #4: cc42a684cc86: Pull complete Step #4: c7997b4917ac: Verifying Checksum Step #4: c7997b4917ac: Download complete Step #4: cf2e8929c5d2: Pull complete Step #4: 53dc9df53f1f: Verifying Checksum Step #4: 53dc9df53f1f: Download complete Step #4: 8fb0b5be246f: Verifying Checksum Step #4: 8fb0b5be246f: Download complete Step #4: bdd9722b34e4: Verifying Checksum Step #4: bdd9722b34e4: Download complete Step #4: c8181fa11e67: Pull complete Step #4: 3b47b475d1e5: Verifying Checksum Step #4: 3b47b475d1e5: Download complete Step #4: 27c36f21ce6c: Pull complete Step #4: fdd56c8ed1fe: Verifying Checksum Step #4: fdd56c8ed1fe: Download complete Step #4: e9487f394bbf: Verifying Checksum Step #4: e9487f394bbf: Download complete Step #4: c01e504f77ea: Verifying Checksum Step #4: c01e504f77ea: Download complete Step #4: ed78c72f0edc: Verifying Checksum Step #4: ed78c72f0edc: Download complete Step #4: b9bc039bd211: Verifying Checksum Step #4: b9bc039bd211: Download complete Step #4: dfd94ecde904: Verifying Checksum Step #4: dfd94ecde904: Download complete Step #4: 1e91a5bf9d06: Verifying Checksum Step #4: 1e91a5bf9d06: Download complete Step #4: 5054ea471fa9: Pull complete Step #4: d6250e629dd4: Pull complete Step #4: 27e64bf5af43: Pull complete Step #4: c5ff56ffb0e4: Pull complete Step #4: 8fb0b5be246f: Pull complete Step #4: 476d1bd54eba: Pull complete Step #4: b65bb9c2b3ee: Pull complete Step #4: 7f20d5b45eae: Pull complete Step #4: ed78c72f0edc: Pull complete Step #4: 28420101279a: Pull complete Step #4: 1e91a5bf9d06: Pull complete Step #4: c7997b4917ac: Pull complete Step #4: 53dc9df53f1f: Pull complete Step #4: dfd94ecde904: Pull complete Step #4: bdd9722b34e4: Pull complete Step #4: 3b47b475d1e5: Pull complete Step #4: e9487f394bbf: Pull complete Step #4: fdd56c8ed1fe: Pull complete Step #4: b9bc039bd211: Pull complete Step #4: c01e504f77ea: Pull complete Step #4: Digest: sha256:63b9e5b74942040e292a43e85778b8728888d62c735991ccfbd0318ed83f3ac7 Step #4: Status: Downloaded newer image for gcr.io/oss-fuzz-base/base-runner:latest Step #4: gcr.io/oss-fuzz-base/base-runner:latest Finished Step #4 Starting Step #5 Step #5: Already have image (with digest): gcr.io/oss-fuzz-base/base-runner Step #5: Running fuzz_gltf Step #5: Running fuzz_gltf_customjson Step #5: Error occured while running fuzz_gltf_customjson: Step #5: Cov returncode: 0, grep returncode: 0 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3682371492 Step #5: INFO: Loaded 1 modules (17518 inline 8-bit counters): 17518 [0x55b98b2d6178, 0x55b98b2da5e6), Step #5: INFO: Loaded 1 PC tables (17518 PCs): 17518 [0x55b98b2da5e8,0x55b98b31ecc8), Step #5: MERGE-OUTER: 9423 files, 0 in the initial corpus, 0 processed earlier Step #5: MERGE-OUTER: attempt 1 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3682461944 Step #5: INFO: Loaded 1 modules (17518 inline 8-bit counters): 17518 [0x556c511f6178, 0x556c511fa5e6), Step #5: INFO: Loaded 1 PC tables (17518 PCs): 17518 [0x556c511fa5e8,0x556c5123ecc8), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge50.txt' Step #5: MERGE-INNER: 9423 total files; 0 processed earlier; will process 9423 files now Step #5: #1 pulse cov: 79 ft: 80 exec/s: 0 rss: 38Mb Step #5: #2 pulse cov: 84 ft: 85 exec/s: 0 rss: 38Mb Step #5: #4 pulse cov: 84 ft: 85 exec/s: 0 rss: 38Mb Step #5: #8 pulse cov: 103 ft: 105 exec/s: 0 rss: 38Mb Step #5: #16 pulse cov: 156 ft: 160 exec/s: 0 rss: 39Mb Step #5: #32 pulse cov: 220 ft: 247 exec/s: 0 rss: 39Mb Step #5: #64 pulse cov: 267 ft: 316 exec/s: 0 rss: 40Mb Step #5: #128 pulse cov: 291 ft: 366 exec/s: 0 rss: 41Mb Step #5: #256 pulse cov: 311 ft: 409 exec/s: 0 rss: 43Mb Step #5: #512 pulse cov: 344 ft: 485 exec/s: 0 rss: 46Mb Step #5: #1024 pulse cov: 420 ft: 943 exec/s: 0 rss: 54Mb Step #5: #2048 pulse cov: 985 ft: 2161 exec/s: 0 rss: 57Mb Step #5: #4096 pulse cov: 2998 ft: 7435 exec/s: 0 rss: 65Mb Step #5: ==55== ERROR: libFuzzer: out-of-memory (used: 2075Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 1085541891 bytes in 25733 chunks; quarantined: 632702 bytes in 311 chunks; 43965 other chunks; total chunks: 70009; showing top 95% (at most 8 unique contexts) Step #5: 1058011152 byte(s) (97%) in 1 allocation(s) Step #5: #0 0x556c50f5a8bd in operator new(unsigned long) /src/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:109:35 Step #5: #1 0x556c510842b5 in __libcpp_allocate /usr/local/bin/../include/c++/v1/__new/allocate.h:43:28 Step #5: #2 0x556c510842b5 in allocate /usr/local/bin/../include/c++/v1/__memory/allocator.h:105:14 Step #5: #3 0x556c510842b5 in __allocate_at_least > /usr/local/bin/../include/c++/v1/__memory/allocate_at_least.h:41:19 Step #5: #4 0x556c510842b5 in __split_buffer /usr/local/bin/../include/c++/v1/__split_buffer:330:25 Step #5: #5 0x556c510842b5 in std::__1::vector>::__append(unsigned long) /usr/local/bin/../include/c++/v1/__vector/vector.h:966:49 Step #5: #6 0x556c50f81e40 in resize /usr/local/bin/../include/c++/v1/__vector/vector.h:1370:11 Step #5: #7 0x556c50f81e40 in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2740:18 Step #5: #8 0x556c51083ca2 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x556c51083ca2 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x556c51083ca2 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x556c51083ca2 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x556c510aa764 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x556c510aa764 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x556c510aa764 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x556c510aa764 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(tinygltf_json const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x556c50faf0c2 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(tinygltf_json const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x556c50f950eb in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x556c50ff4e95 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x556c50ff4e95 in fuzz_ascii /src/tinygltf/tests/fuzzer/build/../fuzz_gltf_customjson.cc:40:11 Step #5: #20 0x556c50ff4e95 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf_customjson.cc:72:5 Step #5: #21 0x556c50df958d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x556c50e02b28 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x556c50dea029 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x556c50e15d02 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7f03691a6082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: operator new(unsigned long)--__libcpp_allocate--allocate Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x3a,0x7b,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x2c,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0xff,0x22,0x3a,0x35,0x2c,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x6a,0x70,0x65,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x43,0x41,0x41,0x43,0x41,0x41,0x41,0x41,0x41,0x49,0x47,0x41,0x2f,0x41,0x2f,0x31,0x2f,0x41,0x39,0x2f,0x2f,0x41,0x69,0x49,0x41,0x41,0x41,0x41,0x41,0x43,0x41,0x41,0x22,0x2c,0x22,0xcc,0x22,0x3a,0x30,0x7d,0x5d,0x7d, Step #5: :{\"asset\":{\"version\":\"\"},\"images\":[{\"\377\":5,\"uri\":\"data:image/jpeg;base64,CAACAAAAAIGA/A/1/A9//AiIAAAAACAA\",\"\314\":0}]} Step #5: artifact_prefix='./'; Test unit written to ./oom-8d2deb5a91f74fe36916243a5ff7c8145b1c3eba Step #5: Base64: OnsiYXNzZXQiOnsidmVyc2lvbiI6IiJ9LCJpbWFnZXMiOlt7Iv8iOjUsInVyaSI6ImRhdGE6aW1hZ2UvanBlZztiYXNlNjQsQ0FBQ0FBQUFBSUdBL0EvMS9BOS8vQWlJQUFBQUFDQUEiLCLMIjowfV19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3834611099 Step #5: INFO: Loaded 1 modules (17518 inline 8-bit counters): 17518 [0x55e8d93b5178, 0x55e8d93b95e6), Step #5: INFO: Loaded 1 PC tables (17518 PCs): 17518 [0x55e8d93b95e8,0x55e8d93fdcc8), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge50.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf_customjson/8d2deb5a91f74fe36916243a5ff7c8145b1c3eba' caused a failure at the previous merge step Step #5: MERGE-INNER: 9423 total files; 4986 processed earlier; will process 4437 files now Step #5: #1 pulse cov: 512 ft: 513 exec/s: 0 rss: 37Mb Step #5: #2 pulse cov: 846 ft: 903 exec/s: 0 rss: 73Mb Step #5: #4 pulse cov: 947 ft: 1118 exec/s: 0 rss: 73Mb Step #5: #8 pulse cov: 1373 ft: 1610 exec/s: 0 rss: 575Mb Step #5: #16 pulse cov: 1549 ft: 1996 exec/s: 2 rss: 575Mb Step #5: #32 pulse cov: 1723 ft: 2452 exec/s: 1 rss: 681Mb Step #5: #64 pulse cov: 2026 ft: 3441 exec/s: 2 rss: 681Mb Step #5: #128 pulse cov: 2396 ft: 4525 exec/s: 2 rss: 681Mb Step #5: #256 pulse cov: 2644 ft: 5724 exec/s: 3 rss: 880Mb Step #5: #512 pulse cov: 2894 ft: 7406 exec/s: 4 rss: 880Mb Step #5: #1024 pulse cov: 3101 ft: 9710 exec/s: 7 rss: 1278Mb Step #5: #2048 pulse cov: 3181 ft: 12702 exec/s: 12 rss: 1278Mb Step #5: #4096 pulse cov: 3207 ft: 16357 exec/s: 14 rss: 1278Mb Step #5: #4437 DONE cov: 3209 ft: 16489 exec/s: 15 rss: 1278Mb Step #5: MERGE-OUTER: successful in 2 attempt(s) Step #5: MERGE-OUTER: the control file has 1177688 bytes Step #5: MERGE-OUTER: consumed 0Mb (48Mb rss) to parse the control file Step #5: MERGE-OUTER: 3755 new files with 17277 new features added; 3543 new coverage edges Step #5: [2026-07-14 07:14:45,314 INFO] Finding shared libraries for targets (if any). Step #5: [2026-07-14 07:14:45,324 INFO] Finished finding shared libraries for targets. Step #5: Coverage error, creating log file: /workspace/out/libfuzzer-coverage-x86_64/fuzzer_stats/fuzz_gltf_customjson_error.log Step #5: Error occured while running fuzz_gltf: Step #5: Cov returncode: 0, grep returncode: 0 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3682352003 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x560fd4e016b0, 0x560fd4e0624b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x560fd4e06250,0x560fd4e51c00), Step #5: MERGE-OUTER: 12701 files, 0 in the initial corpus, 0 processed earlier Step #5: MERGE-OUTER: attempt 1 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3682445123 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x56376ade66b0, 0x56376adeb24b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x56376adeb250,0x56376ae36c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: 12701 total files; 0 processed earlier; will process 12701 files now Step #5: #1 pulse cov: 79 ft: 80 exec/s: 0 rss: 37Mb Step #5: #2 pulse cov: 79 ft: 80 exec/s: 0 rss: 37Mb Step #5: #4 pulse cov: 242 ft: 252 exec/s: 0 rss: 38Mb Step #5: #8 pulse cov: 341 ft: 383 exec/s: 0 rss: 38Mb Step #5: #16 pulse cov: 400 ft: 447 exec/s: 0 rss: 38Mb Step #5: #32 pulse cov: 443 ft: 497 exec/s: 0 rss: 39Mb Step #5: #64 pulse cov: 496 ft: 574 exec/s: 0 rss: 40Mb Step #5: #128 pulse cov: 615 ft: 784 exec/s: 0 rss: 41Mb Step #5: #256 pulse cov: 712 ft: 1004 exec/s: 0 rss: 43Mb Step #5: #512 pulse cov: 836 ft: 1310 exec/s: 0 rss: 48Mb Step #5: #1024 pulse cov: 995 ft: 2071 exec/s: 0 rss: 56Mb Step #5: #2048 pulse cov: 1277 ft: 3850 exec/s: 0 rss: 58Mb Step #5: #4096 pulse cov: 3595 ft: 10946 exec/s: 4096 rss: 66Mb Step #5: ==53== ERROR: libFuzzer: out-of-memory (used: 2353Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 1098939480 bytes in 34694 chunks; quarantined: 274909225 bytes in 1857 chunks; 57562 other chunks; total chunks: 94113; showing top 95% (at most 8 unique contexts) Step #5: 1070785424 byte(s) (97%) in 1 allocation(s) Step #5: #0 0x56376aad5ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x56376abd52dd in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x56376abd52dd in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6813:35 Step #5: #3 0x56376aba2c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x56376aba2c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x56376ab1a219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x56376ab3fcec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x56376ab3fcec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x56376ac27f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x56376ac27f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x56376ac27f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x56376ac27f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x56376ac7e637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x56376ac7e637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x56376ac7e637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x56376ac7e637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x56376ab6a509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x56376ab55889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x56376aba1925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x56376aba1925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x56376aba1925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x56376a9b757d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x56376a9c0b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x56376a9a8019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x56376a9d3cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7f5624ccb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x70,0x6e,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x52,0x30,0x6c,0x47,0x4f,0x44,0x64,0x68,0x30,0x41,0x79,0x44,0x79,0x79,0x61,0x79,0x79,0x79,0x47,0x44,0x4c,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/png;base64,R0lGODdh0AyDyyayyyGDL\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-b022316f018acffa67feb49e6e98b826cc14a429 Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxSMGxHT0RkaDBBeUR5eWF5eXlHREwifV0sImFzc2V0Ijp7InZlcnNpb24iOiIifX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 2 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3689578400 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x561da3f266b0, 0x561da3f2b24b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x561da3f2b250,0x561da3f76c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/b022316f018acffa67feb49e6e98b826cc14a429' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 5454 processed earlier; will process 7247 files now Step #5: #1 pulse cov: 767 ft: 768 exec/s: 0 rss: 37Mb Step #5: #2 pulse cov: 1004 ft: 1160 exec/s: 0 rss: 38Mb Step #5: #4 pulse cov: 1135 ft: 1407 exec/s: 0 rss: 38Mb Step #5: #8 pulse cov: 1271 ft: 1593 exec/s: 0 rss: 39Mb Step #5: #16 pulse cov: 1712 ft: 2699 exec/s: 0 rss: 40Mb Step #5: #32 pulse cov: 2129 ft: 3840 exec/s: 0 rss: 41Mb Step #5: ==60== ERROR: libFuzzer: out-of-memory (used: 2112Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 1582207611 bytes in 22397 chunks; quarantined: 2602743 bytes in 8474 chunks; 29523 other chunks; total chunks: 60394; showing top 95% (at most 8 unique contexts) Step #5: 690908856 byte(s) (43%) in 1 allocation(s) Step #5: #0 0x561da3c15ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x561da3d152aa in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x561da3d152aa in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6812:28 Step #5: #3 0x561da3ce2c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x561da3ce2c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x561da3c5a219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x561da3c7fcec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x561da3c7fcec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x561da3d67f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x561da3d67f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x561da3d67f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x561da3d67f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x561da3dbe637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x561da3dbe637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x561da3dbe637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x561da3dbe637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x561da3caa509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x561da3c95889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x561da3ce1925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x561da3ce1925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x561da3ce1925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x561da3af757d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x561da3b00b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x561da3ae8019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x561da3b13cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fbd232dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: 690908856 byte(s) (43%) in 1 allocation(s) Step #5: #0 0x561da3c15ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x561da3d152dd in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x561da3d152dd in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6813:35 Step #5: #3 0x561da3ce2c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x561da3ce2c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x561da3c5a219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x561da3c7fcec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x561da3c7fcec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x561da3d67f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x561da3d67f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x561da3d67f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x561da3d67f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x561da3dbe637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x561da3dbe637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x561da3dbe637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x561da3dbe637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x561da3caa509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x561da3c95889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x561da3ce1925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x561da3ce1925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x561da3ce1925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x561da3af757d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x561da3b00b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x561da3ae8019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x561da3b13cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fbd232dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: 172727214 byte(s) (10%) in 1 allocation(s) Step #5: #0 0x561da3c15ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x561da3d15315 in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x561da3d15315 in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6814:32 Step #5: #3 0x561da3ce2c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x561da3ce2c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x561da3c5a219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x561da3c7fcec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x561da3c7fcec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x561da3d67f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x561da3d67f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x561da3d67f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x561da3d67f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x561da3dbe637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x561da3dbe637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x561da3dbe637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x561da3dbe637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x561da3caa509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x561da3c95889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x561da3ce1925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x561da3ce1925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x561da3ce1925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x561da3af757d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x561da3b00b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x561da3ae8019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x561da3b13cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fbd232dc082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x70,0x6e,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x52,0x30,0x6c,0x47,0x4f,0x44,0x64,0x68,0x63,0x61,0x6d,0x4f,0x44,0x79,0x79,0x79,0x79,0x79,0x47,0x35,0x30,0x38,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/png;base64,R0lGODdhcamODyyyyyG508\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-20d40020c20793200bf1c8c5d100eea0f53f65a3 Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxSMGxHT0RkaGNhbU9EeXl5eXlHNTA4In1dLCJhc3NldCI6eyJ2ZXJzaW9uIjoiIn19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 3 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3690707576 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x55a1687076b0, 0x55a16870c24b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x55a16870c250,0x55a168757c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/20d40020c20793200bf1c8c5d100eea0f53f65a3' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 5515 processed earlier; will process 7186 files now Step #5: #1 pulse cov: 707 ft: 708 exec/s: 0 rss: 39Mb Step #5: #2 pulse cov: 744 ft: 757 exec/s: 0 rss: 40Mb Step #5: #4 pulse cov: 873 ft: 916 exec/s: 0 rss: 92Mb Step #5: #8 pulse cov: 1296 ft: 1627 exec/s: 0 rss: 92Mb Step #5: #16 pulse cov: 1510 ft: 2095 exec/s: 0 rss: 92Mb Step #5: #32 pulse cov: 2051 ft: 2987 exec/s: 32 rss: 1532Mb Step #5: ==64== ERROR: libFuzzer: out-of-memory (used: 2346Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 2155058197 bytes in 20422 chunks; quarantined: 8255061 bytes in 6292 chunks; 29751 other chunks; total chunks: 56465; showing top 95% (at most 8 unique contexts) Step #5: 945544192 byte(s) (43%) in 1 allocation(s) Step #5: #0 0x55a1683f6ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55a1684f62aa in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55a1684f62aa in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6812:28 Step #5: #3 0x55a1684c3c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x55a1684c3c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x55a16843b219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x55a168460cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x55a168460cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x55a168548f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x55a168548f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x55a168548f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x55a168548f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x55a16859f637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x55a16859f637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x55a16859f637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x55a16859f637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x55a16848b509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x55a168476889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x55a1684c2925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x55a1684c2925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x55a1684c2925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x55a1682d857d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x55a1682e1b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x55a1682c9019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x55a1682f4cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7f532c74c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: 945544192 byte(s) (43%) in 1 allocation(s) Step #5: #0 0x55a1683f6ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55a1684f62dd in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55a1684f62dd in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6813:35 Step #5: #3 0x55a1684c3c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x55a1684c3c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x55a16843b219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x55a168460cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x55a168460cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x55a168548f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x55a168548f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x55a168548f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x55a168548f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x55a16859f637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x55a16859f637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x55a16859f637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x55a16859f637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x55a16848b509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x55a168476889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x55a1684c2925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x55a1684c2925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x55a1684c2925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x55a1682d857d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x55a1682e1b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x55a1682c9019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x55a1682f4cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7f532c74c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: 236386048 byte(s) (10%) in 1 allocation(s) Step #5: #0 0x55a1683f6ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55a1684f6315 in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55a1684f6315 in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6814:32 Step #5: #3 0x55a1684c3c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x55a1684c3c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x55a16843b219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x55a168460cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x55a168460cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x55a168548f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x55a168548f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x55a168548f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x55a168548f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x55a16859f637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x55a16859f637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x55a16859f637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x55a16859f637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x55a16848b509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x55a168476889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x55a1684c2925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x55a1684c2925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x55a1684c2925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x55a1682d857d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x55a1682e1b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x55a1682c9019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x55a1682f4cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7f532c74c082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x70,0x6e,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x52,0x30,0x6c,0x47,0x4f,0x44,0x64,0x68,0x67,0x4f,0x61,0x6d,0x44,0x79,0x79,0x79,0x79,0x79,0x45,0x6d,0x61,0x53,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/png;base64,R0lGODdhgOamDyyyyyEmaS\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-d2be5ccf6064a323a21d76919eae8522c9cf712d Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxSMGxHT0RkaGdPYW1EeXl5eXlFbWFTIn1dLCJhc3NldCI6eyJ2ZXJzaW9uIjoiIn19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 4 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3692838817 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x55d84da526b0, 0x55d84da5724b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x55d84da57250,0x55d84daa2c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/d2be5ccf6064a323a21d76919eae8522c9cf712d' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 5556 processed earlier; will process 7145 files now Step #5: #1 pulse cov: 753 ft: 754 exec/s: 0 rss: 41Mb Step #5: #2 pulse cov: 781 ft: 809 exec/s: 0 rss: 41Mb Step #5: #4 pulse cov: 821 ft: 866 exec/s: 0 rss: 42Mb Step #5: #8 pulse cov: 1087 ft: 1334 exec/s: 0 rss: 42Mb Step #5: #16 pulse cov: 1320 ft: 1694 exec/s: 16 rss: 1528Mb Step #5: #32 pulse cov: 1656 ft: 2338 exec/s: 16 rss: 1528Mb Step #5: #64 pulse cov: 1802 ft: 2647 exec/s: 3 rss: 1864Mb Step #5: #128 pulse cov: 2339 ft: 3602 exec/s: 2 rss: 1864Mb Step #5: ==68== ERROR: libFuzzer: out-of-memory (used: 2105Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 1101884907 bytes in 22377 chunks; quarantined: 9286826 bytes in 232 chunks; 34092 other chunks; total chunks: 56701; showing top 95% (at most 8 unique contexts) Step #5: 1074222740 byte(s) (97%) in 1 allocation(s) Step #5: #0 0x55d84d7848ad in operator new(unsigned long) /src/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:109:35 Step #5: #1 0x55d84d894533 in __libcpp_allocate /usr/local/bin/../include/c++/v1/__new/allocate.h:43:28 Step #5: #2 0x55d84d894533 in allocate /usr/local/bin/../include/c++/v1/__memory/allocator.h:105:14 Step #5: #3 0x55d84d894533 in __allocate_at_least > /usr/local/bin/../include/c++/v1/__memory/allocate_at_least.h:41:19 Step #5: #4 0x55d84d894533 in __split_buffer /usr/local/bin/../include/c++/v1/__split_buffer:330:25 Step #5: #5 0x55d84d894533 in std::__1::vector>::__append(unsigned long) /usr/local/bin/../include/c++/v1/__vector/vector.h:966:49 Step #5: #6 0x55d84d7ac950 in resize /usr/local/bin/../include/c++/v1/__vector/vector.h:1370:11 Step #5: #7 0x55d84d7ac950 in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2740:18 Step #5: #8 0x55d84d893f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x55d84d893f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x55d84d893f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x55d84d893f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x55d84d8ea637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x55d84d8ea637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x55d84d8ea637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x55d84d8ea637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x55d84d7d6509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x55d84d7c1889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x55d84d80d925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x55d84d80d925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x55d84d80d925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x55d84d62357d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x55d84d62cb18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x55d84d614019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x55d84d63fcf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7efdec954082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: operator new(unsigned long)--__libcpp_allocate--allocate Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x62,0x6d,0x70,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x67,0x41,0x41,0x44,0x2b,0x61,0x57,0x73,0x73,0x65,0x2f,0x2f,0x62,0x57,0x69,0x65,0x2f,0x36,0x35,0x42,0x41,0x78,0x67,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/bmp;base64,gAAD+aWsse//bWie/65BAxg\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-2106f19a26641e94a661714ed1b5856b7cbb59cf Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvYm1wO2Jhc2U2NCxnQUFEK2FXc3NlLy9iV2llLzY1QkF4ZyJ9XSwiYXNzZXQiOnsidmVyc2lvbiI6IiJ9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 5 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3771976756 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x55a81e0f36b0, 0x55a81e0f824b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x55a81e0f8250,0x55a81e143c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/2106f19a26641e94a661714ed1b5856b7cbb59cf' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 5724 processed earlier; will process 6977 files now Step #5: #1 pulse cov: 842 ft: 843 exec/s: 0 rss: 59Mb Step #5: #2 pulse cov: 926 ft: 947 exec/s: 0 rss: 122Mb Step #5: #4 pulse cov: 981 ft: 1055 exec/s: 0 rss: 492Mb Step #5: #8 pulse cov: 1256 ft: 1593 exec/s: 1 rss: 492Mb Step #5: #16 pulse cov: 1314 ft: 1709 exec/s: 1 rss: 1544Mb Step #5: #32 pulse cov: 1392 ft: 1880 exec/s: 1 rss: 1544Mb Step #5: #64 pulse cov: 2038 ft: 3017 exec/s: 2 rss: 1544Mb Step #5: #128 pulse cov: 2329 ft: 3990 exec/s: 2 rss: 1544Mb Step #5: #256 pulse cov: 2997 ft: 6150 exec/s: 3 rss: 1915Mb Step #5: ==72== ERROR: libFuzzer: out-of-memory (used: 2275Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 150697038 bytes in 28834 chunks; quarantined: 10465227 bytes in 474 chunks; 35731 other chunks; total chunks: 65039; showing top 95% (at most 8 unique contexts) Step #5: 102752209 byte(s) (68%) in 1 allocation(s) Step #5: #0 0x55a81dde2ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55a81dec4f1e in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55a81dec4f1e in stbi__malloc_mad3 /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1056:11 Step #5: #3 0x55a81dec4f1e in load_jpeg_image /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:3920:28 Step #5: #4 0x55a81dec4f1e in stbi__jpeg_load(stbi__context*, int*, int*, int*, int, stbi__result_info*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:4035:13 Step #5: #5 0x55a81deb0324 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1166:35 Step #5: #6 0x55a81de27219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #7 0x55a81de4ccec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #8 0x55a81de4ccec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #9 0x55a81df34f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #10 0x55a81df34f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #11 0x55a81df34f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #12 0x55a81df34f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #13 0x55a81df8b637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #14 0x55a81df8b637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #15 0x55a81df8b637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #16 0x55a81df8b637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #17 0x55a81de77509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #18 0x55a81de62889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #19 0x55a81deae925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #20 0x55a81deae925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #21 0x55a81deae925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #22 0x55a81dcc457d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #23 0x55a81dccdb18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #24 0x55a81dcb5019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #25 0x55a81dce0cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #26 0x7f5ea8743082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__malloc_mad3 Step #5: 24383096 byte(s) (16%) in 11 allocation(s) Step #5: #0 0x55a81dde2ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55a81e00c253 in operator new(unsigned long) cxa_noexception.cpp Step #5: #2 0x55a81dce0cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #3 0x7f5ea8743082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--operator new(unsigned long)--main Step #5: 20005101 byte(s) (13%) in 3 allocation(s) Step #5: #0 0x55a81dde2ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55a81def55ba in stbi__process_frame_header(stbi__jpeg*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:3335:33 Step #5: #2 0x55a81deeca91 in stbi__decode_jpeg_header(stbi__jpeg*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:3383:9 Step #5: #3 0x55a81debd06c in stbi__decode_jpeg_image /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:3418:9 Step #5: #4 0x55a81debd06c in load_jpeg_image /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:3872:9 Step #5: #5 0x55a81debd06c in stbi__jpeg_load(stbi__context*, int*, int*, int*, int, stbi__result_info*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:4035:13 Step #5: #6 0x55a81deb0324 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1166:35 Step #5: #7 0x55a81de27219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #8 0x55a81de4ccec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #9 0x55a81de4ccec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #10 0x55a81df34f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #11 0x55a81df34f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #12 0x55a81df34f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #13 0x55a81df34f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #14 0x55a81df8b637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #15 0x55a81df8b637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #16 0x55a81df8b637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #17 0x55a81df8b637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #18 0x55a81de77509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #19 0x55a81de62889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #20 0x55a81deae925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #21 0x55a81deae925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #22 0x55a81deae925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #23 0x55a81dcc457d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #24 0x55a81dccdb18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #25 0x55a81dcb5019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #26 0x55a81dce0cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #27 0x7f5ea8743082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__process_frame_header(stbi__jpeg*, int)--stbi__decode_jpeg_header(stbi__jpeg*, int) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x70,0x6e,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x2f,0x2f,0x2f,0x59,0x2f,0x2f,0x2f,0x41,0x41,0x42,0x45,0x49,0x76,0x33,0x38,0x43,0x44,0x41,0x4e,0x48,0x51,0x51,0x4f,0x45,0x49,0x51,0x44,0x69,0x45,0x7a,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/png;base64,///Y///AABEIv38CDANHQQOEIQDiEz\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-e0adc75d988d942ff9ea333d3af3f53a2a9a8f03 Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCwvLy9ZLy8vQUFCRUl2MzhDREFOSFFRT0VJUURpRXoifV0sImFzc2V0Ijp7InZlcnNpb24iOiIifX0= Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 6 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3896114494 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x55bad3fb56b0, 0x55bad3fba24b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x55bad3fba250,0x55bad4005c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/e0adc75d988d942ff9ea333d3af3f53a2a9a8f03' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 6221 processed earlier; will process 6480 files now Step #5: #1 pulse cov: 834 ft: 835 exec/s: 0 rss: 44Mb Step #5: #2 pulse cov: 844 ft: 875 exec/s: 0 rss: 46Mb Step #5: #4 pulse cov: 1015 ft: 1217 exec/s: 4 rss: 915Mb Step #5: #8 pulse cov: 1347 ft: 1759 exec/s: 8 rss: 915Mb Step #5: #16 pulse cov: 1557 ft: 2219 exec/s: 5 rss: 1274Mb Step #5: #32 pulse cov: 1978 ft: 2904 exec/s: 4 rss: 1534Mb Step #5: #64 pulse cov: 2098 ft: 3455 exec/s: 4 rss: 1534Mb Step #5: ==80== ERROR: libFuzzer: out-of-memory (used: 2064Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 1326855974 bytes in 22120 chunks; quarantined: 9136105 bytes in 1117 chunks; 33340 other chunks; total chunks: 56577; showing top 95% (at most 8 unique contexts) Step #5: 577424160 byte(s) (43%) in 1 allocation(s) Step #5: #0 0x55bad3ca4ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55bad3da42aa in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55bad3da42aa in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6812:28 Step #5: #3 0x55bad3d71c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x55bad3d71c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x55bad3ce9219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x55bad3d0ecec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x55bad3d0ecec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x55bad3df6f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x55bad3df6f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x55bad3df6f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x55bad3df6f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x55bad3e4d637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x55bad3e4d637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x55bad3e4d637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x55bad3e4d637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x55bad3d39509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x55bad3d24889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x55bad3d70925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x55bad3d70925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x55bad3d70925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x55bad3b8657d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x55bad3b8fb18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x55bad3b77019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x55bad3ba2cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fd8f1f73082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: 577424160 byte(s) (43%) in 1 allocation(s) Step #5: #0 0x55bad3ca4ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55bad3da42dd in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55bad3da42dd in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6813:35 Step #5: #3 0x55bad3d71c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x55bad3d71c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x55bad3ce9219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x55bad3d0ecec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x55bad3d0ecec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x55bad3df6f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x55bad3df6f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x55bad3df6f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x55bad3df6f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x55bad3e4d637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x55bad3e4d637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x55bad3e4d637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x55bad3e4d637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x55bad3d39509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x55bad3d24889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x55bad3d70925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x55bad3d70925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x55bad3d70925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x55bad3b8657d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x55bad3b8fb18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x55bad3b77019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x55bad3ba2cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fd8f1f73082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: 144356040 byte(s) (10%) in 1 allocation(s) Step #5: #0 0x55bad3ca4ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55bad3da4315 in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55bad3da4315 in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6814:32 Step #5: #3 0x55bad3d71c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x55bad3d71c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x55bad3ce9219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x55bad3d0ecec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x55bad3d0ecec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x55bad3df6f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x55bad3df6f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x55bad3df6f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x55bad3df6f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x55bad3e4d637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x55bad3e4d637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x55bad3e4d637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x55bad3e4d637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x55bad3d39509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x55bad3d24889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x55bad3d70925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x55bad3d70925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x55bad3d70925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x55bad3b8657d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x55bad3b8fb18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x55bad3b77019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x55bad3ba2cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fd8f1f73082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x70,0x6e,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x52,0x30,0x6c,0x47,0x4f,0x44,0x6c,0x68,0x2f,0x4a,0x6c,0x4f,0x44,0x72,0x72,0x72,0x72,0x72,0x72,0x2b,0x2f,0x2f,0x2f,0x2f,0x31,0x37,0x2f,0x35,0x2f,0x2f,0x73,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/png;base64,R0lGODlh/JlODrrrrrr+////17/5//s\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-be736f8ae029f6dfe0e05cd14644173308ca087f Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxSMGxHT0RsaC9KbE9EcnJycnJyKy8vLy8xNy81Ly9zIn1dLCJhc3NldCI6eyJ2ZXJzaW9uIjoiIn19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 7 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3916246638 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x5628edf9d6b0, 0x5628edfa224b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x5628edfa2250,0x5628edfedc00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/be736f8ae029f6dfe0e05cd14644173308ca087f' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 6336 processed earlier; will process 6365 files now Step #5: #1 pulse cov: 836 ft: 837 exec/s: 0 rss: 49Mb Step #5: #2 pulse cov: 935 ft: 972 exec/s: 0 rss: 50Mb Step #5: #4 pulse cov: 1069 ft: 1184 exec/s: 0 rss: 50Mb Step #5: #8 pulse cov: 1340 ft: 1621 exec/s: 8 rss: 851Mb Step #5: #16 pulse cov: 1619 ft: 2108 exec/s: 4 rss: 1369Mb Step #5: #32 pulse cov: 1821 ft: 2513 exec/s: 8 rss: 1369Mb Step #5: #64 pulse cov: 2439 ft: 3950 exec/s: 7 rss: 1379Mb Step #5: ==84== ERROR: libFuzzer: out-of-memory (used: 2249Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 2082161809 bytes in 23852 chunks; quarantined: 2023851 bytes in 2783 chunks; 29912 other chunks; total chunks: 56547; showing top 95% (at most 8 unique contexts) Step #5: 1027220560 byte(s) (49%) in 1 allocation(s) Step #5: #0 0x5628edccf8ad in operator new(unsigned long) /src/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:109:35 Step #5: #1 0x5628edddf533 in __libcpp_allocate /usr/local/bin/../include/c++/v1/__new/allocate.h:43:28 Step #5: #2 0x5628edddf533 in allocate /usr/local/bin/../include/c++/v1/__memory/allocator.h:105:14 Step #5: #3 0x5628edddf533 in __allocate_at_least > /usr/local/bin/../include/c++/v1/__memory/allocate_at_least.h:41:19 Step #5: #4 0x5628edddf533 in __split_buffer /usr/local/bin/../include/c++/v1/__split_buffer:330:25 Step #5: #5 0x5628edddf533 in std::__1::vector>::__append(unsigned long) /usr/local/bin/../include/c++/v1/__vector/vector.h:966:49 Step #5: #6 0x5628edcf7950 in resize /usr/local/bin/../include/c++/v1/__vector/vector.h:1370:11 Step #5: #7 0x5628edcf7950 in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2740:18 Step #5: #8 0x5628edddef20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x5628edddef20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x5628edddef20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x5628edddef20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x5628ede35637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x5628ede35637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x5628ede35637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x5628ede35637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x5628edd21509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x5628edd0c889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x5628edd58925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x5628edd58925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x5628edd58925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x5628edb6e57d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x5628edb77b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x5628edb5f019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x5628edb8acf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7f9e39e79082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: operator new(unsigned long)--__libcpp_allocate--allocate Step #5: 1027220560 byte(s) (49%) in 1 allocation(s) Step #5: #0 0x5628edc8ced4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x5628edd8c2aa in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x5628edd8c2aa in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6812:28 Step #5: #3 0x5628edd59c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x5628edd59c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x5628edcd1219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x5628edcf6cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x5628edcf6cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x5628edddef20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x5628edddef20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x5628edddef20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x5628edddef20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x5628ede35637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x5628ede35637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x5628ede35637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x5628ede35637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x5628edd21509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x5628edd0c889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x5628edd58925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x5628edd58925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x5628edd58925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x5628edb6e57d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x5628edb77b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x5628edb5f019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x5628edb8acf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7f9e39e79082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x70,0x6e,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x52,0x30,0x6c,0x47,0x4f,0x44,0x64,0x68,0x59,0x30,0x44,0x63,0x50,0x41,0x41,0x41,0x79,0x79,0x79,0x79,0x47,0x4c,0x41,0x41,0x41,0x51,0x64,0x68,0x41,0x4f,0x48,0x58,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/png;base64,R0lGODdhY0DcPAAAyyyyGLAAAQdhAOHX\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-add8de1f358ede802d542be115f76bd8081c9666 Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxSMGxHT0RkaFkwRGNQQUFBeXl5eUdMQUFBUWRoQU9IWCJ9XSwiYXNzZXQiOnsidmVyc2lvbiI6IiJ9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 8 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3934465603 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x55c4850476b0, 0x55c48504c24b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x55c48504c250,0x55c485097c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/add8de1f358ede802d542be115f76bd8081c9666' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 6450 processed earlier; will process 6251 files now Step #5: #1 pulse cov: 727 ft: 728 exec/s: 0 rss: 40Mb Step #5: #2 pulse cov: 957 ft: 1162 exec/s: 0 rss: 40Mb Step #5: #4 pulse cov: 1071 ft: 1304 exec/s: 0 rss: 40Mb Step #5: #8 pulse cov: 1183 ft: 1604 exec/s: 2 rss: 1355Mb Step #5: #16 pulse cov: 1693 ft: 2610 exec/s: 5 rss: 1355Mb Step #5: #32 pulse cov: 2374 ft: 4003 exec/s: 3 rss: 1526Mb Step #5: #64 pulse cov: 2694 ft: 5045 exec/s: 5 rss: 1526Mb Step #5: ==88== ERROR: libFuzzer: out-of-memory (used: 2103Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 103593606 bytes in 23690 chunks; quarantined: 8442721 bytes in 771 chunks; 36219 other chunks; total chunks: 60680; showing top 95% (at most 8 unique contexts) Step #5: 75879120 byte(s) (73%) in 1 allocation(s) Step #5: #0 0x55c484d36ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55c484e04a27 in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55c484e04a27 in stbi__malloc_mad3 /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1056:11 Step #5: #3 0x55c484e04a27 in stbi__bmp_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:5616:22 Step #5: #4 0x55c484e04a27 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1148:35 Step #5: #5 0x55c484d7b219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x55c484da0cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x55c484da0cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x55c484e88f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x55c484e88f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x55c484e88f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x55c484e88f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x55c484edf637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x55c484edf637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x55c484edf637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x55c484edf637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x55c484dcb509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x55c484db6889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x55c484e02925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x55c484e02925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x55c484e02925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x55c484c1857d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x55c484c21b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x55c484c09019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x55c484c34cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fcfd22f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__malloc_mad3 Step #5: 24383096 byte(s) (23%) in 11 allocation(s) Step #5: #0 0x55c484d36ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55c484f60253 in operator new(unsigned long) cxa_noexception.cpp Step #5: #2 0x55c484c34cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #3 0x7fcfd22f3082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--operator new(unsigned long)--main Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x70,0x6e,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x51,0x6b,0x33,0x31,0x43,0x61,0x6e,0x69,0x61,0x69,0x6d,0x51,0x6e,0x69,0x4d,0x41,0x41,0x41,0x41,0x4d,0x41,0x41,0x41,0x41,0x4c,0x71,0x6d,0x32,0x41,0x51,0x45,0x41,0x42,0x41,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/png;base64,Qk31CaniaimQniMAAAAMAAAALqm2AQEABA\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-d7b914db57fef9a17148ce6e93e70af358e7fbc2 Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxRazMxQ2FuaWFpbVFuaU1BQUFBTUFBQUFMcW0yQVFFQUJBIn1dLCJhc3NldCI6eyJ2ZXJzaW9uIjoiIn19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 9 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3952588936 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x561c4b8416b0, 0x561c4b84624b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x561c4b846250,0x561c4b891c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/d7b914db57fef9a17148ce6e93e70af358e7fbc2' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 6532 processed earlier; will process 6169 files now Step #5: #1 pulse cov: 761 ft: 762 exec/s: 0 rss: 42Mb Step #5: #2 pulse cov: 959 ft: 1040 exec/s: 1 rss: 1064Mb Step #5: #4 pulse cov: 1014 ft: 1120 exec/s: 2 rss: 1064Mb Step #5: #8 pulse cov: 1119 ft: 1255 exec/s: 4 rss: 1064Mb Step #5: #16 pulse cov: 1442 ft: 1684 exec/s: 2 rss: 1064Mb Step #5: ==92== ERROR: libFuzzer: out-of-memory (used: 2368Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 1240978877 bytes in 17749 chunks; quarantined: 10232778 bytes in 1268 chunks; 33287 other chunks; total chunks: 52304; showing top 95% (at most 8 unique contexts) Step #5: 1213501144 byte(s) (97%) in 1 allocation(s) Step #5: #32 pulse cov: 1559 ft: 2068 exec/s: 2 rss: 2368Mb Step #5: #0 0x561c4b5738ad in operator new(unsigned long) /src/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:109:35 Step #5: #1 0x561c4b683533 in __libcpp_allocate /usr/local/bin/../include/c++/v1/__new/allocate.h:43:28 Step #5: #2 0x561c4b683533 in allocate /usr/local/bin/../include/c++/v1/__memory/allocator.h:105:14 Step #5: #3 0x561c4b683533 in __allocate_at_least > /usr/local/bin/../include/c++/v1/__memory/allocate_at_least.h:41:19 Step #5: #4 0x561c4b683533 in __split_buffer /usr/local/bin/../include/c++/v1/__split_buffer:330:25 Step #5: #5 0x561c4b683533 in std::__1::vector>::__append(unsigned long) /usr/local/bin/../include/c++/v1/__vector/vector.h:966:49 Step #5: #6 0x561c4b59b950 in resize /usr/local/bin/../include/c++/v1/__vector/vector.h:1370:11 Step #5: #7 0x561c4b59b950 in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2740:18 Step #5: #8 0x561c4b682f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x561c4b682f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x561c4b682f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x561c4b682f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x561c4b6d9637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x561c4b6d9637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x561c4b6d9637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x561c4b6d9637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x561c4b5c5509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x561c4b5b0889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x561c4b5fc925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x561c4b5fc925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x561c4b5fc925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x561c4b41257d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x561c4b41bb18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x561c4b403019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x561c4b42ecf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7f64ddf05082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: operator new(unsigned long)--__libcpp_allocate--allocate Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x70,0x6e,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x51,0x6b,0x31,0x35,0x43,0x2b,0x6d,0x79,0x42,0x41,0x41,0x45,0x71,0x48,0x6f,0x41,0x41,0x41,0x41,0x4d,0x41,0x41,0x41,0x41,0x2f,0x33,0x38,0x36,0x41,0x41,0x45,0x41,0x47,0x41,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/png;base64,Qk15C+myBAAEqHoAAAAMAAAA/386AAEAGA\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-89077bc3374077e78045ed5007509cc85e7dc7be Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxRazE1QytteUJBQUVxSG9BQUFBTUFBQUEvMzg2QUFFQUdBIn1dLCJhc3NldCI6eyJ2ZXJzaW9uIjoiIn19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 10 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3966715002 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x55e9607336b0, 0x55e96073824b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x55e960738250,0x55e960783c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/89077bc3374077e78045ed5007509cc85e7dc7be' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 6566 processed earlier; will process 6135 files now Step #5: #1 pulse cov: 715 ft: 716 exec/s: 0 rss: 40Mb Step #5: #2 pulse cov: 813 ft: 865 exec/s: 0 rss: 379Mb Step #5: #4 pulse cov: 942 ft: 1024 exec/s: 0 rss: 379Mb Step #5: #8 pulse cov: 1175 ft: 1356 exec/s: 2 rss: 427Mb Step #5: #16 pulse cov: 1375 ft: 1756 exec/s: 5 rss: 427Mb Step #5: ==96== ERROR: libFuzzer: out-of-memory (used: 2212Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 78317146 bytes in 18316 chunks; quarantined: 9366797 bytes in 703 chunks; 33271 other chunks; total chunks: 52290; showing top 95% (at most 8 unique contexts) Step #5: 50817084 byte(s) (64%) in 1 allocation(s) Step #5: #0 0x55e960422ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55e9604f0a27 in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55e9604f0a27 in stbi__malloc_mad3 /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1056:11 Step #5: #3 0x55e9604f0a27 in stbi__bmp_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:5616:22 Step #5: #4 0x55e9604f0a27 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1148:35 Step #5: #5 0x55e960467219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x55e96048ccec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x55e96048ccec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x55e960574f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x55e960574f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x55e960574f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x55e960574f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x55e9605cb637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x55e9605cb637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x55e9605cb637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x55e9605cb637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x55e9604b7509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x55e9604a2889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x55e9604ee925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x55e9604ee925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x55e9604ee925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x55e96030457d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x55e96030db18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x55e9602f5019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x55e960320cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7f777bdb1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__malloc_mad3 Step #5: 24383096 byte(s) (31%) in 11 allocation(s) Step #5: #0 0x55e960422ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55e96064c253 in operator new(unsigned long) cxa_noexception.cpp Step #5: #2 0x55e960320cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #3 0x7f777bdb1082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--operator new(unsigned long)--main Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x70,0x6e,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x51,0x6b,0x32,0x79,0x43,0x61,0x6e,0x69,0x61,0x69,0x6d,0x51,0x6e,0x69,0x6f,0x43,0x41,0x41,0x41,0x4d,0x41,0x41,0x41,0x41,0x71,0x57,0x4c,0x33,0x41,0x51,0x45,0x41,0x42,0x41,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/png;base64,Qk2yCaniaimQnioCAAAMAAAAqWL3AQEABA\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-9fd5a59c6beb1d260e64cdf32e2b300ea2d95cae Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxRazJ5Q2FuaWFpbVFuaW9DQUFBTUFBQUFxV0wzQVFFQUJBIn1dLCJhc3NldCI6eyJ2ZXJzaW9uIjoiIn19 Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 11 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 3975840629 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x561a065416b0, 0x561a0654624b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x561a06546250,0x561a06591c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/9fd5a59c6beb1d260e64cdf32e2b300ea2d95cae' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 6598 processed earlier; will process 6103 files now Step #5: #1 pulse cov: 786 ft: 787 exec/s: 0 rss: 58Mb Step #5: #2 pulse cov: 809 ft: 860 exec/s: 0 rss: 58Mb Step #5: #4 pulse cov: 1038 ft: 1299 exec/s: 0 rss: 58Mb Step #5: #8 pulse cov: 1125 ft: 1424 exec/s: 0 rss: 58Mb Step #5: #16 pulse cov: 1419 ft: 1875 exec/s: 0 rss: 58Mb Step #5: #32 pulse cov: 1679 ft: 2370 exec/s: 10 rss: 564Mb Step #5: #64 pulse cov: 2181 ft: 3406 exec/s: 4 rss: 876Mb Step #5: #128 pulse cov: 2680 ft: 4713 exec/s: 4 rss: 1572Mb Step #5: #256 pulse cov: 3101 ft: 6377 exec/s: 5 rss: 1885Mb Step #5: #512 pulse cov: 3663 ft: 9194 exec/s: 3 rss: 1885Mb Step #5: ==100== ERROR: libFuzzer: out-of-memory (used: 2102Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 1103586941 bytes in 31496 chunks; quarantined: 7599463 bytes in 940 chunks; 32641 other chunks; total chunks: 65077; showing top 95% (at most 8 unique contexts) Step #5: 1075560420 byte(s) (97%) in 1 allocation(s) Step #5: #0 0x561a062738ad in operator new(unsigned long) /src/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:109:35 Step #5: #1 0x561a06383533 in __libcpp_allocate /usr/local/bin/../include/c++/v1/__new/allocate.h:43:28 Step #5: #2 0x561a06383533 in allocate /usr/local/bin/../include/c++/v1/__memory/allocator.h:105:14 Step #5: #3 0x561a06383533 in __allocate_at_least > /usr/local/bin/../include/c++/v1/__memory/allocate_at_least.h:41:19 Step #5: #4 0x561a06383533 in __split_buffer /usr/local/bin/../include/c++/v1/__split_buffer:330:25 Step #5: #5 0x561a06383533 in std::__1::vector>::__append(unsigned long) /usr/local/bin/../include/c++/v1/__vector/vector.h:966:49 Step #5: #6 0x561a0629b950 in resize /usr/local/bin/../include/c++/v1/__vector/vector.h:1370:11 Step #5: #7 0x561a0629b950 in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2740:18 Step #5: #8 0x561a06382f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x561a06382f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x561a06382f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x561a06382f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x561a063d9637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x561a063d9637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x561a063d9637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x561a063d9637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x561a062c5509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x561a062b0889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x561a062fc925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x561a062fc925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x561a062fc925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x561a0611257d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x561a0611bb18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x561a06103019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x561a0612ecf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7f9af57bb082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: operator new(unsigned long)--__libcpp_allocate--allocate Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x62,0x6d,0x70,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x2f,0x2f,0x2f,0x59,0x2f,0x2f,0x2f,0x43,0x41,0x42,0x51,0x49,0x45,0x41,0x66,0x2f,0x2f,0x77,0x51,0x48,0x45,0x67,0x45,0x45,0x45,0x67,0x45,0x4c,0x49,0x67,0x48,0x50,0x45,0x68,0x26,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x62,0x2f,0x2f,0x2f,0x43,0x41,0x42,0x51,0x49,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/bmp;base64,///Y///CABQIEAf//wQHEgEEEgELIgHPEh&\"}],\"asset\":{\"version\":\"b///CABQI\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-c8f5d1376dc91517ec91eb6d9b67fa225022b2ed Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvYm1wO2Jhc2U2NCwvLy9ZLy8vQ0FCUUlFQWYvL3dRSEVnRUVFZ0VMSWdIUEVoJiJ9XSwiYXNzZXQiOnsidmVyc2lvbiI6ImIvLy9DQUJRSSJ9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 12 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4221025963 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x56320464b6b0, 0x56320465024b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x563204650250,0x56320469bc00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/c8f5d1376dc91517ec91eb6d9b67fa225022b2ed' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 7326 processed earlier; will process 5375 files now Step #5: #1 pulse cov: 692 ft: 693 exec/s: 0 rss: 43Mb Step #5: #2 pulse cov: 967 ft: 1171 exec/s: 0 rss: 44Mb Step #5: #4 pulse cov: 1098 ft: 1463 exec/s: 0 rss: 45Mb Step #5: #8 pulse cov: 1359 ft: 1926 exec/s: 4 rss: 491Mb Step #5: #16 pulse cov: 1567 ft: 2312 exec/s: 1 rss: 1528Mb Step #5: #32 pulse cov: 2143 ft: 3466 exec/s: 1 rss: 1528Mb Step #5: #64 pulse cov: 2718 ft: 4903 exec/s: 1 rss: 1530Mb Step #5: #128 pulse cov: 3022 ft: 5742 exec/s: 2 rss: 1548Mb Step #5: ==144== ERROR: libFuzzer: out-of-memory (used: 2230Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 2302677692 bytes in 26902 chunks; quarantined: 9498532 bytes in 213 chunks; 33771 other chunks; total chunks: 60886; showing top 95% (at most 8 unique contexts) Step #5: 1011037800 byte(s) (43%) in 1 allocation(s) Step #5: #0 0x56320433aed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x56320443a2dd in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x56320443a2dd in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6813:35 Step #5: #3 0x563204407c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x563204407c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x56320437f219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x5632043a4cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x5632043a4cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x56320448cf20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x56320448cf20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x56320448cf20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x56320448cf20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x5632044e3637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x5632044e3637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x5632044e3637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x5632044e3637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x5632043cf509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x5632043ba889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x563204406925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x563204406925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x563204406925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x56320421c57d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x563204225b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x56320420d019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x563204238cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fa3cb965082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: 1011037800 byte(s) (43%) in 1 allocation(s) Step #5: #0 0x56320433aed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x56320443a2aa in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x56320443a2aa in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6812:28 Step #5: #3 0x563204407c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x563204407c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x56320437f219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x5632043a4cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x5632043a4cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x56320448cf20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x56320448cf20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x56320448cf20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x56320448cf20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x5632044e3637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x5632044e3637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x5632044e3637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x5632044e3637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x5632043cf509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x5632043ba889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x563204406925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x563204406925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x563204406925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x56320421c57d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x563204225b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x56320420d019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x563204238cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fa3cb965082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: 252759450 byte(s) (10%) in 1 allocation(s) Step #5: #0 0x56320433aed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x56320443a315 in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x56320443a315 in stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:6814:32 Step #5: #3 0x563204407c53 in stbi__gif_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:7074:8 Step #5: #4 0x563204407c53 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1151:35 Step #5: #5 0x56320437f219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x5632043a4cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x5632043a4cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x56320448cf20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x56320448cf20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x56320448cf20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x56320448cf20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x5632044e3637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x5632044e3637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x5632044e3637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x5632044e3637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x5632043cf509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x5632043ba889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x563204406925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x563204406925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x563204406925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x56320421c57d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x563204225b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x56320420d019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x563204238cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fa3cb965082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__gif_load_next(stbi__context*, stbi__gif*, int*, int, unsigned char*) Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x70,0x6e,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x52,0x30,0x6c,0x47,0x4f,0x44,0x6c,0x68,0x74,0x66,0x6c,0x79,0x44,0x79,0x4f,0x79,0x79,0x79,0x79,0x79,0x41,0x41,0x41,0x41,0x41,0x6c,0x47,0x4f,0x44,0x64,0x68,0x63,0x61,0x6d,0x4f,0x44,0x79,0x41,0x41,0x41,0x2f,0x2f,0x2f,0x35,0x2f,0x2f,0x73,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/png;base64,R0lGODlhtflyDyOyyyyyAAAAAlGODdhcamODyAAA///5//s\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-774898c7d9d09d13211fd6e8a1a7d479545d3dd2 Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxSMGxHT0RsaHRmbHlEeU95eXl5eUFBQUFBbEdPRGRoY2FtT0R5QUFBLy8vNS8vcyJ9XSwiYXNzZXQiOnsidmVyc2lvbiI6IiJ9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 13 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 4287169072 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x55deb69076b0, 0x55deb690c24b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x55deb690c250,0x55deb6957c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/774898c7d9d09d13211fd6e8a1a7d479545d3dd2' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 7516 processed earlier; will process 5185 files now Step #5: #1 pulse cov: 575 ft: 576 exec/s: 0 rss: 41Mb Step #5: #2 pulse cov: 789 ft: 960 exec/s: 0 rss: 42Mb Step #5: #4 pulse cov: 1013 ft: 1448 exec/s: 0 rss: 42Mb Step #5: #8 pulse cov: 1574 ft: 2215 exec/s: 0 rss: 87Mb Step #5: #16 pulse cov: 1940 ft: 3182 exec/s: 2 rss: 1512Mb Step #5: #32 pulse cov: 2452 ft: 4371 exec/s: 3 rss: 1512Mb Step #5: #64 pulse cov: 2882 ft: 5750 exec/s: 4 rss: 2502Mb Step #5: ==148== ERROR: libFuzzer: out-of-memory (used: 2502Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 204064822 bytes in 24884 chunks; quarantined: 8741480 bytes in 1807 chunks; 34054 other chunks; total chunks: 60745; showing top 95% (at most 8 unique contexts) Step #5: 121967641 byte(s) (59%) in 1 allocation(s) Step #5: #0 0x55deb65f6ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55deb66d8f1e in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55deb66d8f1e in stbi__malloc_mad3 /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1056:11 Step #5: #3 0x55deb66d8f1e in load_jpeg_image /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:3920:28 Step #5: #4 0x55deb66d8f1e in stbi__jpeg_load(stbi__context*, int*, int*, int*, int, stbi__result_info*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:4035:13 Step #5: #5 0x55deb66c4324 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1166:35 Step #5: #6 0x55deb663b219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #7 0x55deb6660cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #8 0x55deb6660cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #9 0x55deb6748f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #10 0x55deb6748f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #11 0x55deb6748f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #12 0x55deb6748f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #13 0x55deb679f637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #14 0x55deb679f637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #15 0x55deb679f637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #16 0x55deb679f637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #17 0x55deb668b509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #18 0x55deb6676889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #19 0x55deb66c2925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #20 0x55deb66c2925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #21 0x55deb66c2925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #22 0x55deb64d857d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #23 0x55deb64e1b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #24 0x55deb64c9019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #25 0x55deb64f4cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #26 0x7f9f38814082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__malloc_mad3 Step #5: 54185660 byte(s) (26%) in 4 allocation(s) Step #5: #0 0x55deb65f6ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55deb67095ba in stbi__process_frame_header(stbi__jpeg*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:3335:33 Step #5: #2 0x55deb6700a91 in stbi__decode_jpeg_header(stbi__jpeg*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:3383:9 Step #5: #3 0x55deb66d106c in stbi__decode_jpeg_image /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:3418:9 Step #5: #4 0x55deb66d106c in load_jpeg_image /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:3872:9 Step #5: #5 0x55deb66d106c in stbi__jpeg_load(stbi__context*, int*, int*, int*, int, stbi__result_info*) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:4035:13 Step #5: #6 0x55deb66c4324 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1166:35 Step #5: #7 0x55deb663b219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #8 0x55deb6660cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #9 0x55deb6660cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #10 0x55deb6748f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #11 0x55deb6748f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #12 0x55deb6748f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #13 0x55deb6748f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #14 0x55deb679f637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #15 0x55deb679f637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #16 0x55deb679f637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #17 0x55deb679f637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #18 0x55deb668b509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #19 0x55deb6676889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #20 0x55deb66c2925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #21 0x55deb66c2925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #22 0x55deb66c2925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #23 0x55deb64d857d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #24 0x55deb64e1b18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #25 0x55deb64c9019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #26 0x55deb64f4cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #27 0x7f9f38814082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__process_frame_header(stbi__jpeg*, int)--stbi__decode_jpeg_header(stbi__jpeg*, int) Step #5: 24383096 byte(s) (11%) in 11 allocation(s) Step #5: #0 0x55deb65f6ed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55deb6820253 in operator new(unsigned long) cxa_noexception.cpp Step #5: #2 0x55deb64f4cf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #3 0x7f9f38814082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--operator new(unsigned long)--main Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x6a,0x70,0x65,0x67,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x2f,0x2f,0x2f,0x59,0x2f,0x2f,0x2f,0x41,0x41,0x42,0x51,0x49,0x41,0x36,0x4b,0x41,0x45,0x77,0x51,0x48,0x45,0x51,0x45,0x48,0x49,0x51,0x45,0x45,0x45,0x67,0x45,0x45,0x45,0x67,0x50,0x2f,0x36,0x41,0x41,0x45,0x45,0x67,0x50,0x2f,0x34,0x65,0x67,0x72,0x69,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/jpeg;base64,///Y///AABQIA6KAEwQHEQEHIQEEEgEEEgP/6AAEEgP/4egri\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-7e84a93d1d72110cc4cb402a94a09be03ccaa7a5 Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvanBlZztiYXNlNjQsLy8vWS8vL0FBQlFJQTZLQUV3UUhFUUVISVFFRUVnRUVFZ1AvNkFBRUVnUC80ZWdyaSJ9XSwiYXNzZXQiOnsidmVyc2lvbiI6IiJ9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 14 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 8325517 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x55c1b15d06b0, 0x55c1b15d524b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x55c1b15d5250,0x55c1b1620c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/7e84a93d1d72110cc4cb402a94a09be03ccaa7a5' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 7584 processed earlier; will process 5117 files now Step #5: #1 pulse cov: 786 ft: 787 exec/s: 0 rss: 41Mb Step #5: #2 pulse cov: 1016 ft: 1202 exec/s: 0 rss: 42Mb Step #5: #4 pulse cov: 1159 ft: 1418 exec/s: 0 rss: 61Mb Step #5: #8 pulse cov: 1543 ft: 2055 exec/s: 0 rss: 1531Mb Step #5: #16 pulse cov: 1935 ft: 2984 exec/s: 0 rss: 1531Mb Step #5: #32 pulse cov: 2268 ft: 4124 exec/s: 10 rss: 1531Mb Step #5: #64 pulse cov: 2773 ft: 5528 exec/s: 6 rss: 1531Mb Step #5: #128 pulse cov: 3213 ft: 7533 exec/s: 6 rss: 1908Mb Step #5: #256 pulse cov: 3570 ft: 9219 exec/s: 10 rss: 1908Mb Step #5: #512 pulse cov: 3914 ft: 11592 exec/s: 8 rss: 1908Mb Step #5: #1024 pulse cov: 4120 ft: 13932 exec/s: 4 rss: 1908Mb Step #5: ==152== ERROR: libFuzzer: out-of-memory (used: 2145Mb; limit: 2048Mb) Step #5: To change the out-of-memory limit use -rss_limit_mb= Step #5: Step #5: Live Heap Allocations: 97591079 bytes in 36826 chunks; quarantined: 6907728 bytes in 1504 chunks; 31019 other chunks; total chunks: 69349; showing top 95% (at most 8 unique contexts) Step #5: 69351296 byte(s) (71%) in 1 allocation(s) Step #5: #0 0x55c1b12bfed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55c1b138da27 in stbi__malloc /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:985:12 Step #5: #2 0x55c1b138da27 in stbi__malloc_mad3 /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1056:11 Step #5: #3 0x55c1b138da27 in stbi__bmp_load /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:5616:22 Step #5: #4 0x55c1b138da27 in stbi__load_main(stbi__context*, int*, int*, int*, int, stbi__result_info*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1148:35 Step #5: #5 0x55c1b1304219 in stbi__load_and_postprocess_8bit(stbi__context*, int*, int*, int*, int) /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1261:19 Step #5: #6 0x55c1b1329cec in stbi_load_from_memory /src/tinygltf/tests/fuzzer/build/../../../stb_image.h:1431:11 Step #5: #7 0x55c1b1329cec in tinygltf::LoadImageData(tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:2673:14 Step #5: #8 0x55c1b1411f20 in __invoke, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:87:27 Step #5: #9 0x55c1b1411f20 in __call, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:336:12 Step #5: #10 0x55c1b1411f20 in __invoke_r, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *), tinygltf::Image *, int, std::__1::basic_string, std::__1::allocator > *, std::__1::basic_string, std::__1::allocator > *, int, int, const unsigned char *, int, void *> /usr/local/bin/../include/c++/v1/__type_traits/invoke.h:350:10 Step #5: #11 0x55c1b1411f20 in std::__1::__function::__func, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*), bool (tinygltf::Image*, int, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, int, int, unsigned char const*, int, void*)>::operator()(tinygltf::Image*&&, int&&, std::__1::basic_string, std::__1::allocator>*&&, std::__1::basic_string, std::__1::allocator>*&&, int&&, int&&, unsigned char const*&&, int&&, void*&&) /usr/local/bin/../include/c++/v1/__functional/function.h:174:12 Step #5: #12 0x55c1b1468637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:274:12 Step #5: #13 0x55c1b1468637 in operator() /usr/local/bin/../include/c++/v1/__functional/function.h:772:10 Step #5: #14 0x55c1b1468637 in ParseImage /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:4445:10 Step #5: #15 0x55c1b1468637 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10::operator()(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&) const /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6425:12 Step #5: #16 0x55c1b1354509 in bool tinygltf::detail::ForEachInArray, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10>(nlohmann::basic_json, std::__1::allocator>, bool, long, unsigned long, double, std::__1::allocator, nlohmann::adl_serializer, std::__1::vector>> const&, char const*, tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int)::$_10&&) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:5981:12 Step #5: #17 0x55c1b133f889 in tinygltf::TinyGLTF::LoadFromString(tinygltf::Model*, std::__1::basic_string, std::__1::allocator>*, std::__1::basic_string, std::__1::allocator>*, char const*, unsigned int, std::__1::basic_string, std::__1::allocator> const&, unsigned int) /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6417:20 Step #5: #18 0x55c1b138b925 in LoadASCIIFromString /src/tinygltf/tests/fuzzer/build/../../../tiny_gltf.h:6708:10 Step #5: #19 0x55c1b138b925 in parse_intCoding4 /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:22:18 Step #5: #20 0x55c1b138b925 in LLVMFuzzerTestOneInput /src/tinygltf/tests/fuzzer/build/../fuzz_gltf.cc:30:5 Step #5: #21 0x55c1b11a157d in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:619:13 Step #5: #22 0x55c1b11aab18 in fuzzer::Fuzzer::CrashResistantMergeInternalStep(std::__Fuzzer::basic_string, std::__Fuzzer::allocator> const&, bool) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMerge.cpp:239:5 Step #5: #23 0x55c1b1192019 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:890:8 Step #5: #24 0x55c1b11bdcf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #25 0x7fdb57318082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--stbi__malloc--stbi__malloc_mad3 Step #5: 24383096 byte(s) (24%) in 11 allocation(s) Step #5: #0 0x55c1b12bfed4 in malloc /src/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3 Step #5: #1 0x55c1b14e9253 in operator new(unsigned long) cxa_noexception.cpp Step #5: #2 0x55c1b11bdcf2 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 Step #5: #3 0x7fdb57318082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 5792732f783158c66fb4f3756458ca24e46e827d) Step #5: Step #5: DEDUP_TOKEN: __interceptor_malloc--operator new(unsigned long)--main Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: 0x7b,0x22,0x69,0x6d,0x61,0x67,0x65,0x73,0x22,0x3a,0x5b,0x7b,0x22,0x75,0x72,0x69,0x22,0x3a,0x22,0x64,0x61,0x74,0x61,0x3a,0x69,0x6d,0x61,0x67,0x65,0x2f,0x67,0x69,0x66,0x3b,0x62,0x61,0x73,0x65,0x36,0x34,0x2c,0x51,0x6b,0x32,0x34,0x6a,0x2f,0x2f,0x74,0x72,0x73,0x78,0x61,0x65,0x30,0x67,0x41,0x41,0x41,0x41,0x6f,0x41,0x41,0x41,0x41,0x59,0x49,0x6b,0x41,0x41,0x4f,0x30,0x42,0x41,0x41,0x41,0x42,0x41,0x43,0x41,0x41,0x41,0x77,0x41,0x41,0x41,0x41,0x74,0x72,0x73,0x78,0x61,0x65,0x30,0x67,0x41,0x41,0x41,0x41,0x6f,0x41,0x41,0x50,0x41,0x41,0x6d,0x65,0x73,0x68,0x65,0x59,0x49,0x6b,0x41,0x41,0x41,0x4f,0x39,0x41,0x43,0x30,0x42,0x77,0x41,0x41,0x41,0x41,0x41,0x43,0x41,0x41,0x41,0x54,0x38,0x35,0x35,0x33,0x37,0x50,0x50,0x61,0x2f,0x2f,0x2f,0x31,0x33,0x2f,0x6c,0x2f,0x2f,0x61,0x22,0x7d,0x5d,0x2c,0x22,0x61,0x73,0x73,0x65,0x74,0x22,0x3a,0x7b,0x22,0x76,0x65,0x72,0x73,0x69,0x6f,0x6e,0x22,0x3a,0x22,0x22,0x7d,0x7d, Step #5: {\"images\":[{\"uri\":\"data:image/gif;base64,Qk24j//trsxae0gAAAAoAAAAYIkAAO0BAAABACAAAwAAAAtrsxae0gAAAAoAAPAAmesheYIkAAAO9AC0BwAAAAACAAAT85537PPa///13/l//a\"}],\"asset\":{\"version\":\"\"}} Step #5: artifact_prefix='./'; Test unit written to ./oom-ea933ec2afb767599ee9887061c7954e03393772 Step #5: Base64: eyJpbWFnZXMiOlt7InVyaSI6ImRhdGE6aW1hZ2UvZ2lmO2Jhc2U2NCxRazI0ai8vdHJzeGFlMGdBQUFBb0FBQUFZSWtBQU8wQkFBQUJBQ0FBQXdBQUFBdHJzeGFlMGdBQUFBb0FBUEFBbWVzaGVZSWtBQUFPOUFDMEJ3QUFBQUFDQUFBVDg1NTM3UFBhLy8vMTMvbC8vYSJ9XSwiYXNzZXQiOnsidmVyc2lvbiI6IiJ9fQ== Step #5: SUMMARY: libFuzzer: out-of-memory Step #5: MERGE-OUTER: attempt 15 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 288498028 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x56482029b6b0, 0x5648202a024b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x5648202a0250,0x5648202ebc00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/ea933ec2afb767599ee9887061c7954e03393772' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 8894 processed earlier; will process 3807 files now Step #5: #1 pulse cov: 736 ft: 737 exec/s: 0 rss: 42Mb Step #5: #2 pulse cov: 895 ft: 1065 exec/s: 0 rss: 42Mb Step #5: #4 pulse cov: 1146 ft: 1588 exec/s: 0 rss: 43Mb Step #5: #8 pulse cov: 1564 ft: 2432 exec/s: 8 rss: 146Mb Step #5: #16 pulse cov: 2125 ft: 4095 exec/s: 3 rss: 1389Mb Step #5: #32 pulse cov: 2519 ft: 5060 exec/s: 6 rss: 1389Mb Step #5: #64 pulse cov: 3041 ft: 6984 exec/s: 2 rss: 1389Mb Step #5: #128 pulse cov: 3480 ft: 9143 exec/s: 2 rss: 1901Mb Step #5: #256 pulse cov: 3795 ft: 11344 exec/s: 3 rss: 1901Mb Step #5: #512 pulse cov: 4014 ft: 14227 exec/s: 4 rss: 1901Mb Step #5: #1024 pulse cov: 4268 ft: 17107 exec/s: 5 rss: 1901Mb Step #5: #2048 pulse cov: 4388 ft: 21946 exec/s: 5 rss: 1901Mb Step #5: AddressSanitizer:DEADLYSIGNAL Step #5: ================================================================= Step #5: ==156==ERROR: AddressSanitizer: stack-overflow on address 0x7ffc2c465ff0 (pc 0x56481ffb8854 bp 0x000000000000 sp 0x7ffc2c465fe0 T0) Step #5: ==156==ABORTING Step #5: MS: 0 ; base unit: 0000000000000000000000000000000000000000 Step #5: artifact_prefix='./'; Test unit written to ./crash-f71704490c5264022a4d4e07a5dafa56c6c4115a Step #5: MERGE-OUTER: attempt 16 Step #5: INFO: Running with entropic power schedule (0xFF, 100). Step #5: INFO: Seed: 850770879 Step #5: INFO: Loaded 1 modules (19355 inline 8-bit counters): 19355 [0x55bcd3e636b0, 0x55bcd3e6824b), Step #5: INFO: Loaded 1 PC tables (19355 PCs): 19355 [0x55bcd3e68250,0x55bcd3eb3c00), Step #5: INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 1048576 bytes Step #5: MERGE-INNER: using the control file '/tmp/libFuzzerTemp.Merge41.txt' Step #5: MERGE-INNER: '/corpus/fuzz_gltf/f71704490c5264022a4d4e07a5dafa56c6c4115a' caused a failure at the previous merge step Step #5: MERGE-INNER: 12701 total files; 11919 processed earlier; will process 782 files now Step #5: #1 pulse cov: 850 ft: 851 exec/s: 0 rss: 43Mb Step #5: #2 pulse cov: 1043 ft: 1209 exec/s: 0 rss: 48Mb Step #5: #4 pulse cov: 1264 ft: 1716 exec/s: 0 rss: 55Mb Step #5: #8 pulse cov: 1626 ft: 2848 exec/s: 0 rss: 56Mb Step #5: #16 pulse cov: 2450 ft: 4583 exec/s: 0 rss: 64Mb Step #5: #32 pulse cov: 2732 ft: 7014 exec/s: 0 rss: 72Mb Step #5: #64 pulse cov: 3163 ft: 9522 exec/s: 3 rss: 1395Mb Step #5: #128 pulse cov: 3565 ft: 11877 exec/s: 2 rss: 1398Mb Step #5: #256 pulse cov: 3837 ft: 14217 exec/s: 3 rss: 1427Mb Step #5: #512 pulse cov: 3943 ft: 15864 exec/s: 5 rss: 1427Mb Step #5: #782 DONE cov: 4074 ft: 16885 exec/s: 6 rss: 1427Mb Step #5: MERGE-OUTER: successful in 16 attempt(s) Step #5: MERGE-OUTER: the control file has 2318303 bytes Step #5: MERGE-OUTER: consumed 1Mb (60Mb rss) to parse the control file Step #5: MERGE-OUTER: 7801 new files with 28807 new features added; 4941 new coverage edges Step #5: [2026-07-14 07:33:46,262 INFO] Finding shared libraries for targets (if any). Step #5: [2026-07-14 07:33:46,272 INFO] Finished finding shared libraries for targets. Step #5: Coverage error, creating log file: /workspace/out/libfuzzer-coverage-x86_64/fuzzer_stats/fuzz_gltf_error.log Step #5: [2026-07-14 07:33:46,725 INFO] Finding shared libraries for targets (if any). Step #5: [2026-07-14 07:33:46,741 INFO] Finished finding shared libraries for targets. Step #5: [2026-07-14 07:33:47,066 DEBUG] Finished generating per-file code coverage summary. Step #5: [2026-07-14 07:33:47,066 DEBUG] Generating file view html index file as: "/workspace/out/libfuzzer-coverage-x86_64/report/linux/file_view_index.html". Step #5: [2026-07-14 07:33:47,079 DEBUG] Finished generating file view html index file. Step #5: [2026-07-14 07:33:47,079 DEBUG] Calculating per-directory coverage summary. Step #5: [2026-07-14 07:33:47,079 DEBUG] Finished calculating per-directory coverage summary. Step #5: [2026-07-14 07:33:47,079 DEBUG] Writing per-directory coverage html reports. Step #5: [2026-07-14 07:33:47,127 DEBUG] Finished writing per-directory coverage html reports. Step #5: [2026-07-14 07:33:47,127 DEBUG] Generating directory view html index file as: "/workspace/out/libfuzzer-coverage-x86_64/report/linux/directory_view_index.html". Step #5: [2026-07-14 07:33:47,127 DEBUG] Finished generating directory view html index file. Step #5: [2026-07-14 07:33:47,127 INFO] Index file for html report is generated as: "file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/index.html". Step #5: [2026-07-14 07:33:47,420 DEBUG] Finished generating per-file code coverage summary. Step #5: [2026-07-14 07:33:47,420 DEBUG] Generating file view html index file as: "/workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/file_view_index.html". Step #5: [2026-07-14 07:33:47,432 DEBUG] Finished generating file view html index file. Step #5: [2026-07-14 07:33:47,432 DEBUG] Calculating per-directory coverage summary. Step #5: [2026-07-14 07:33:47,432 DEBUG] Finished calculating per-directory coverage summary. Step #5: [2026-07-14 07:33:47,432 DEBUG] Writing per-directory coverage html reports. Step #5: [2026-07-14 07:33:47,481 DEBUG] Finished writing per-directory coverage html reports. Step #5: [2026-07-14 07:33:47,481 DEBUG] Generating directory view html index file as: "/workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/directory_view_index.html". Step #5: [2026-07-14 07:33:47,481 DEBUG] Finished generating directory view html index file. Step #5: [2026-07-14 07:33:47,481 INFO] Index file for html report is generated as: "file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/index.html". Step #5: [2026-07-14 07:33:47,690 DEBUG] Finished generating per-file code coverage summary. Step #5: [2026-07-14 07:33:47,690 DEBUG] Generating file view html index file as: "/workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/file_view_index.html". Step #5: [2026-07-14 07:33:47,702 DEBUG] Finished generating file view html index file. Step #5: [2026-07-14 07:33:47,702 DEBUG] Calculating per-directory coverage summary. Step #5: [2026-07-14 07:33:47,702 DEBUG] Finished calculating per-directory coverage summary. Step #5: [2026-07-14 07:33:47,702 DEBUG] Writing per-directory coverage html reports. Step #5: [2026-07-14 07:33:47,750 DEBUG] Finished writing per-directory coverage html reports. Step #5: [2026-07-14 07:33:47,750 DEBUG] Generating directory view html index file as: "/workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/directory_view_index.html". Step #5: [2026-07-14 07:33:47,750 DEBUG] Finished generating directory view html index file. Step #5: [2026-07-14 07:33:47,750 INFO] Index file for html report is generated as: "file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/index.html". Finished Step #5 Starting Step #6 Step #6: Pulling image: gcr.io/cloud-builders/gsutil Step #6: Using default tag: latest Step #6: latest: Pulling from cloud-builders/gsutil Step #6: 97e1ee089ace: Already exists Step #6: b8613ef18de2: Already exists Step #6: 370a343ae1d7: Already exists Step #6: 1434b9de6cf8: Already exists Step #6: 27737137e53a: Already exists Step #6: 3506d965e444: Already exists Step #6: 51d5de874af4: Pulling fs layer Step #6: ead8998371a3: Pulling fs layer Step #6: ead8998371a3: Verifying Checksum Step #6: ead8998371a3: Download complete Step #6: 51d5de874af4: Verifying Checksum Step #6: 51d5de874af4: Download complete Step #6: 51d5de874af4: Pull complete Step #6: ead8998371a3: Pull complete Step #6: Digest: sha256:5de2330cdc9ab905a9873e91d02bbcd7637aa7b75dbd2524ce8504bfdeadc2bd Step #6: Status: Downloaded newer image for gcr.io/cloud-builders/gsutil:latest Step #6: gcr.io/cloud-builders/gsutil:latest Step #6: CommandException: 1 files/objects could not be removed. Finished Step #6 Starting Step #7 Step #7: Already have image (with digest): gcr.io/cloud-builders/gsutil Step #7: Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/control.js [Content-Type=text/javascript]... Step #7: / [0/18 files][ 0.0 B/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/style.css [Content-Type=text/css]... Step #7: / [0/18 files][ 2.3 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/directory_view_index.html [Content-Type=text/html]... Step #7: / [0/18 files][ 2.3 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/summary.json [Content-Type=application/json]... Step #7: / [0/18 files][ 5.7 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/index.html [Content-Type=text/html]... Step #7: / [0/18 files][ 5.7 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/report.html [Content-Type=text/html]... Step #7: / [0/18 files][ 9.5 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/file_view_index.html [Content-Type=text/html]... Step #7: / [0/18 files][ 9.5 KiB/ 12.0 MiB] 0% Done / [1/18 files][ 9.5 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/report.html [Content-Type=text/html]... Step #7: / [1/18 files][ 9.5 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/tinygltf/tinygltf_json.h.html [Content-Type=text/html]... Step #7: / [1/18 files][ 9.5 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/tinygltf/json.hpp.html [Content-Type=text/html]... Step #7: / [1/18 files][ 9.5 KiB/ 12.0 MiB] 0% Done / [2/18 files][ 9.5 KiB/ 12.0 MiB] 0% Done / [3/18 files][ 9.5 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/tinygltf/report.html [Content-Type=text/html]... Step #7: / [3/18 files][ 13.8 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/tinygltf/stb_image.h.html [Content-Type=text/html]... Step #7: / [3/18 files][ 20.9 KiB/ 12.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/tinygltf/stb_image_write.h.html [Content-Type=text/html]... Step #7: / [3/18 files][ 25.2 KiB/ 12.0 MiB] 0% Done / [4/18 files][ 25.2 KiB/ 12.0 MiB] 0% Done / [5/18 files][464.6 KiB/ 12.0 MiB] 3% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/tinygltf/tiny_gltf.h.html [Content-Type=text/html]... Step #7: / [5/18 files][464.6 KiB/ 12.0 MiB] 3% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/tinygltf/tests/report.html [Content-Type=text/html]... Step #7: / [5/18 files][464.6 KiB/ 12.0 MiB] 3% Done / [6/18 files][471.0 KiB/ 12.0 MiB] 3% Done / [7/18 files][471.0 KiB/ 12.0 MiB] 3% Done / [8/18 files][471.0 KiB/ 12.0 MiB] 3% Done / [9/18 files][471.0 KiB/ 12.0 MiB] 3% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/tinygltf/tests/fuzzer/report.html [Content-Type=text/html]... Step #7: / [9/18 files][ 2.8 MiB/ 12.0 MiB] 23% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/tinygltf/tests/fuzzer/fuzz_gltf_customjson.cc.html [Content-Type=text/html]... Step #7: / [9/18 files][ 4.6 MiB/ 12.0 MiB] 38% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report/linux/src/tinygltf/tests/fuzzer/fuzz_gltf.cc.html [Content-Type=text/html]... Step #7: / [9/18 files][ 5.4 MiB/ 12.0 MiB] 44% Done / [10/18 files][ 6.0 MiB/ 12.0 MiB] 50% Done / [11/18 files][ 12.0 MiB/ 12.0 MiB] 99% Done / [12/18 files][ 12.0 MiB/ 12.0 MiB] 99% Done / [13/18 files][ 12.0 MiB/ 12.0 MiB] 99% Done / [14/18 files][ 12.0 MiB/ 12.0 MiB] 99% Done / [15/18 files][ 12.0 MiB/ 12.0 MiB] 99% Done / [16/18 files][ 12.0 MiB/ 12.0 MiB] 99% Done / [17/18 files][ 12.0 MiB/ 12.0 MiB] 99% Done / [18/18 files][ 12.0 MiB/ 12.0 MiB] 100% Done - Step #7: Operation completed over 18 objects/12.0 MiB. Finished Step #7 Starting Step #8 Step #8: Already have image (with digest): gcr.io/cloud-builders/gsutil Step #8: CommandException: 1 files/objects could not be removed. Finished Step #8 Starting Step #9 Step #9: Already have image (with digest): gcr.io/cloud-builders/gsutil Step #9: Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/control.js [Content-Type=text/javascript]... Step #9: / [0/32 files][ 0.0 B/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/style.css [Content-Type=text/css]... Step #9: / [0/32 files][ 0.0 B/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/directory_view_index.html [Content-Type=text/html]... Step #9: / [0/32 files][ 0.0 B/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/summary.json [Content-Type=application/json]... Step #9: / [0/32 files][ 0.0 B/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/index.html [Content-Type=text/html]... Step #9: / [0/32 files][ 2.3 KiB/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/report.html [Content-Type=text/html]... Step #9: / [0/32 files][ 8.6 KiB/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/file_view_index.html [Content-Type=text/html]... Step #9: / [0/32 files][ 8.6 KiB/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/src/report.html [Content-Type=text/html]... Step #9: / [0/32 files][ 8.6 KiB/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/src/tinygltf/json.hpp.html [Content-Type=text/html]... Step #9: / [0/32 files][ 8.6 KiB/ 14.0 MiB] 0% Done / [1/32 files][ 8.6 KiB/ 14.0 MiB] 0% Done / [2/32 files][ 8.6 KiB/ 14.0 MiB] 0% Done / [3/32 files][ 8.6 KiB/ 14.0 MiB] 0% Done / [4/32 files][ 13.0 KiB/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/src/tinygltf/report.html [Content-Type=text/html]... Step #9: / [4/32 files][ 13.0 KiB/ 14.0 MiB] 0% Done / [5/32 files][ 19.1 KiB/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/src/tinygltf/stb_image.h.html [Content-Type=text/html]... Step #9: / [5/32 files][ 23.4 KiB/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/src/tinygltf/tiny_gltf.h.html [Content-Type=text/html]... Step #9: / [5/32 files][ 23.4 KiB/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/src/tinygltf/stb_image_write.h.html [Content-Type=text/html]... Step #9: / [5/32 files][ 23.4 KiB/ 14.0 MiB] 0% Done / [6/32 files][ 23.4 KiB/ 14.0 MiB] 0% Done / [7/32 files][ 29.4 KiB/ 14.0 MiB] 0% Done / [8/32 files][ 29.4 KiB/ 14.0 MiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/src/tinygltf/tests/report.html [Content-Type=text/html]... Step #9: / [8/32 files][ 1.8 MiB/ 14.0 MiB] 13% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/src/tinygltf/tests/fuzzer/fuzz_gltf.cc.html [Content-Type=text/html]... Step #9: / [8/32 files][ 5.3 MiB/ 14.0 MiB] 37% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/control.js [Content-Type=text/javascript]... Step #9: / [8/32 files][ 5.3 MiB/ 14.0 MiB] 37% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/style.css [Content-Type=text/css]... Step #9: / [8/32 files][ 5.3 MiB/ 14.0 MiB] 37% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/directory_view_index.html [Content-Type=text/html]... Step #9: / [8/32 files][ 5.3 MiB/ 14.0 MiB] 37% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf/linux/src/tinygltf/tests/fuzzer/report.html [Content-Type=text/html]... Step #9: / [8/32 files][ 5.3 MiB/ 14.0 MiB] 37% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/summary.json [Content-Type=application/json]... Step #9: / [8/32 files][ 5.3 MiB/ 14.0 MiB] 37% Done / [9/32 files][ 5.6 MiB/ 14.0 MiB] 39% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/index.html [Content-Type=text/html]... Step #9: / [9/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/report.html [Content-Type=text/html]... Step #9: / [9/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/file_view_index.html [Content-Type=text/html]... Step #9: / [9/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/src/report.html [Content-Type=text/html]... Step #9: / [9/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/src/tinygltf/tinygltf_json.h.html [Content-Type=text/html]... Step #9: / [9/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done / [10/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/src/tinygltf/report.html [Content-Type=text/html]... Step #9: / [10/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/src/tinygltf/stb_image.h.html [Content-Type=text/html]... Step #9: / [10/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/src/tinygltf/stb_image_write.h.html [Content-Type=text/html]... Step #9: / [10/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/src/tinygltf/tiny_gltf.h.html [Content-Type=text/html]... Step #9: / [10/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/src/tinygltf/tests/report.html [Content-Type=text/html]... Step #9: / [10/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done / [11/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done / [12/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/src/tinygltf/tests/fuzzer/report.html [Content-Type=text/html]... Step #9: / [12/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done / [13/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/report_target/fuzz_gltf_customjson/linux/src/tinygltf/tests/fuzzer/fuzz_gltf_customjson.cc.html [Content-Type=text/html]... Step #9: / [14/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done / [14/32 files][ 9.4 MiB/ 14.0 MiB] 67% Done / [15/32 files][ 9.9 MiB/ 14.0 MiB] 70% Done / [16/32 files][ 9.9 MiB/ 14.0 MiB] 70% Done - - [17/32 files][ 9.9 MiB/ 14.0 MiB] 70% Done - [18/32 files][ 9.9 MiB/ 14.0 MiB] 70% Done - [19/32 files][ 9.9 MiB/ 14.0 MiB] 70% Done - [20/32 files][ 9.9 MiB/ 14.0 MiB] 70% Done - [21/32 files][ 9.9 MiB/ 14.0 MiB] 70% Done - [22/32 files][ 9.9 MiB/ 14.0 MiB] 70% Done - [23/32 files][ 10.1 MiB/ 14.0 MiB] 72% Done - [24/32 files][ 10.1 MiB/ 14.0 MiB] 72% Done - [25/32 files][ 10.1 MiB/ 14.0 MiB] 72% Done - [26/32 files][ 10.1 MiB/ 14.0 MiB] 72% Done - [27/32 files][ 10.1 MiB/ 14.0 MiB] 72% Done - [28/32 files][ 14.0 MiB/ 14.0 MiB] 99% Done - [29/32 files][ 14.0 MiB/ 14.0 MiB] 99% Done - [30/32 files][ 14.0 MiB/ 14.0 MiB] 99% Done - [31/32 files][ 14.0 MiB/ 14.0 MiB] 99% Done - [32/32 files][ 14.0 MiB/ 14.0 MiB] 100% Done Step #9: Operation completed over 32 objects/14.0 MiB. Finished Step #9 Starting Step #10 Step #10: Already have image (with digest): gcr.io/cloud-builders/gsutil Step #10: CommandException: 1 files/objects could not be removed. Finished Step #10 Starting Step #11 Step #11: Already have image (with digest): gcr.io/cloud-builders/gsutil Step #11: Copying file:///workspace/out/libfuzzer-coverage-x86_64/fuzzer_stats/fuzz_gltf.json [Content-Type=application/json]... Step #11: / [0/5 files][ 0.0 B/ 6.5 KiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/fuzzer_stats/fuzz_gltf_customjson_error.log [Content-Type=application/octet-stream]... Step #11: / [0/5 files][ 0.0 B/ 6.5 KiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/fuzzer_stats/fuzz_gltf_error.log [Content-Type=application/octet-stream]... Step #11: / [0/5 files][ 0.0 B/ 6.5 KiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/fuzzer_stats/fuzz_gltf_customjson.json [Content-Type=application/json]... Step #11: / [0/5 files][ 0.0 B/ 6.5 KiB] 0% Done Copying file:///workspace/out/libfuzzer-coverage-x86_64/fuzzer_stats/coverage_targets.txt [Content-Type=text/plain]... Step #11: / [0/5 files][ 0.0 B/ 6.5 KiB] 0% Done / [1/5 files][ 6.5 KiB/ 6.5 KiB] 99% Done / [2/5 files][ 6.5 KiB/ 6.5 KiB] 99% Done / [3/5 files][ 6.5 KiB/ 6.5 KiB] 99% Done / [4/5 files][ 6.5 KiB/ 6.5 KiB] 99% Done / [5/5 files][ 6.5 KiB/ 6.5 KiB] 100% Done Step #11: Operation completed over 5 objects/6.5 KiB. Finished Step #11 Starting Step #12 Step #12: Already have image (with digest): gcr.io/cloud-builders/gsutil Step #12: CommandException: 1 files/objects could not be removed. Finished Step #12 Starting Step #13 Step #13: Already have image (with digest): gcr.io/cloud-builders/gsutil Step #13: Copying file:///workspace/out/libfuzzer-coverage-x86_64/textcov_reports/fuzz_gltf.covreport [Content-Type=application/octet-stream]... Step #13: Copying file:///workspace/out/libfuzzer-coverage-x86_64/textcov_reports/fuzz_gltf_customjson.covreport [Content-Type=application/octet-stream]... Step #13: / [0/2 files][ 0.0 B/ 1.2 MiB] 0% Done / [0/2 files][ 0.0 B/ 1.2 MiB] 0% Done / [1/2 files][ 1.2 MiB/ 1.2 MiB] 99% Done / [2/2 files][ 1.2 MiB/ 1.2 MiB] 100% Done Step #13: Operation completed over 2 objects/1.2 MiB. Finished Step #13 Starting Step #14 Step #14: Already have image (with digest): gcr.io/cloud-builders/gsutil Step #14: CommandException: 1 files/objects could not be removed. Finished Step #14 Starting Step #15 Step #15: Already have image (with digest): gcr.io/cloud-builders/gsutil Step #15: Copying file:///workspace/out/libfuzzer-coverage-x86_64/logs/fuzz_gltf_customjson.log [Content-Type=application/octet-stream]... Step #15: Copying file:///workspace/out/libfuzzer-coverage-x86_64/logs/fuzz_gltf.log [Content-Type=application/octet-stream]... Step #15: / [0/2 files][ 0.0 B/242.9 KiB] 0% Done / [0/2 files][ 0.0 B/242.9 KiB] 0% Done / [1/2 files][242.9 KiB/242.9 KiB] 99% Done / [2/2 files][242.9 KiB/242.9 KiB] 100% Done Step #15: Operation completed over 2 objects/242.9 KiB. Finished Step #15 Starting Step #16 Step #16: Already have image (with digest): gcr.io/cloud-builders/gsutil Step #16: Copying file:///workspace/srcmap.json [Content-Type=application/json]... Step #16: / [0 files][ 0.0 B/ 154.0 B] / [1 files][ 154.0 B/ 154.0 B] Step #16: Operation completed over 1 objects/154.0 B. Finished Step #16 Starting Step #17 Step #17: Already have image (with digest): gcr.io/cloud-builders/curl Step #17: % Total % Received % Xferd Average Speed Time Time Time Current Step #17: Dload Upload Total Spent Left Speed Step #17: 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 100 312 0 0 100 312 0 1485 --:--:-- --:--:-- --:--:-- 1485 Finished Step #17 PUSH DONE