New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 603897 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Dec 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug

Blocked on:
issue 615385



Sign in to add a comment

Direct-leak in base::SparseHistogram::FactoryGet

Project Member Reported by ClusterFuzz, Apr 15 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6659650568585216

Fuzzer: media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegDemuxer::OnFindStreamInfoDone
  Run<const base::Callback<void
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95OBS4B2HNtXRjk3ao3vudqxjHWbc2JoVbvLgl6feA_ipKL_7RlWVsMxukmJWzuIAqzoZbLJxr06X13fhe-L834fJsPBFjB_XWTbbIqZJspDfIikCJI3_z9oZ7WLqJifl_Pg5Y3vrsmwYc6lBiszAj4latwcw


Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by mmoroz@chromium.org, Apr 15 2016

Cc: kcc@chromium.org aizatsky@chromium.org
Owner: jrumm...@chromium.org
Project Member

Comment 2 by ClusterFuzz, Apr 15 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5245445479071744

Fuzzer: media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegGlue::OpenContext
  Run
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv946CYKoEQ3ANVBz7qaoMm61k_I4ZZ6VRCxyYqyOk5eywqV_t1kWK6ZIg_h1qC0DFh_9G0rIHNgEKbGIcP-FPeFQznCkHh55RUPhrWEkus252019BZOpYzwnW0GujV9q4v19hYXWHOfUPkCKjwxezWwGj6pVAw


Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 3 by ClusterFuzz, May 30 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5186404552540160

Fuzzer: media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegDemuxer::OnFindStreamInfoDone
  Run<media::FFmpegDemuxer *, const base::Callback<void
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96BE8et8slepIFcotzUqvGt1FtIV9T2LnYdNpUz8BdaTSYLsqfr6dM841NJK_XSNx1smRQtZ0lvHu3swe0z_GA3FETd0yG5Ze4Gb57QvBi0QHMwQ0xQ4Ji7OC8VI4wpGwoyM0Ba49nGS2UV4l6DuRViDGRq3w


Filer: ajha

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 4 by ClusterFuzz, Jun 15 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6615208042954752

Fuzzer: media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegDemuxer::OnFindStreamInfoDone
  Run
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94iHPBMHIaxWGI-X0RCa5Oa4fwWXHs9hCx_NK5jn2VPJDORpN8cyu0hyzUMg_rG0ybRQ5ZSukXpqt-32uS6B28bH0F85iI_QWly1BMklpInL935BT4mnNhojpR8-HFJfpgBtvp10tfMsb0MT5i6VLeZtgNIvw


Filer: durga.behera

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 5 by ClusterFuzz, Jul 13 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4973318914703360

Fuzzer: libfuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegGlue::OpenContext
  Run
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94a_aGgnRe2xqhVpV0pYsnp5UmXHGR5HWXyHKwctSZWyn638wwRhvjL13VMca1KixfQbhKfC7J8Oiq2dKTolw4Yp2UuTjJgqyGRG2sBE50O3hrPvs-2jsxTX1DXM0MxeqC6y5xk7KeQSybjVoE7j8nmAqPPZw?testcase_id=4973318914703360


Filer: mmohammad

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 6 by ClusterFuzz, Jul 14 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6498006031663104

Fuzzer: libfuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegGlue::OpenContext
  Run
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97D7RxEub1XNxQ7Fx6CrTkCK-Lu2aOK63-QWSlVnTEMlM0pzL1Y8WHsJWPzPgW-QwpasMEL0HY4YFpTRIMMGtXGqTv-NBpUrgeY8BFoPqFW4ATuEEO5vb7CA3usztuebiOfVZjJEF9Ibm-kg4YP5CnyQgBfpQ?testcase_id=6498006031663104


Filer: mmohammad

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 7 by ClusterFuzz, Jul 15 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5145108160970752

Fuzzer: media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegDemuxer::OnFindStreamInfoDone
  Invoke<base::WeakPtr<media::FFmpegDemuxer>, const base::Callback<void
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=395675:395769

Minimized Testcase (3.96 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95-ngeV_XWWeVxjgDduijFwWFJ3eFjb0pUao5RH_nR96kAEMSqcHXxG0AC4FEGOCCnLmQCyqDszHnkGoNQFcH_j_BGWCqceC7omU4Uyiyv9aOIjgSC2OUoyNsBgklx5ZSiiwkFJTv6cEm1Y4zN8pXd_VMtFHw?testcase_id=5145108160970752

Filer: ajha

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

Comment 8 by ajha@chromium.org, Jul 15 2016

jrummell@: Could you please take a look at this and confirm if the Crash state of CF update in C#7 is same as this issue or not.


Comment 9 by mmoroz@chromium.org, Jul 15 2016

IIRC, we ignore this because we need to update LSan suppressions for media fuzzers.
Blockedon: 615385
Project Member

Comment 11 by ClusterFuzz, Jul 15 2016

ClusterFuzz has detected this issue as fixed in range 405445:405519.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5145108160970752

Fuzzer: media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegDemuxer::OnFindStreamInfoDone
  Invoke<base::WeakPtr<media::FFmpegDemuxer>, const base::Callback<void
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=395675:395769
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=405445:405519

Minimized Testcase (3.96 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95-ngeV_XWWeVxjgDduijFwWFJ3eFjb0pUao5RH_nR96kAEMSqcHXxG0AC4FEGOCCnLmQCyqDszHnkGoNQFcH_j_BGWCqceC7omU4Uyiyv9aOIjgSC2OUoyNsBgklx5ZSiiwkFJTv6cEm1Y4zN8pXd_VMtFHw?testcase_id=5145108160970752

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 12 by ClusterFuzz, Jul 15 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5678907080835072

Fuzzer: libfuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegGlue::OpenContext
  Run
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv963WFraPG6dG1O36_X55M52khZKexuomSDfXLhhl2c9xQvxxHGYlgk_p2RCIzMJy0RtOmCqRpvksNX3LSPhXnnMb5LKnWqikc5ys6VWSxzVHN8bBekfIIrvxEczXlkZhBrU1EqAWc9IolMKTyI7nD8bwr5NSA?testcase_id=5678907080835072


Filer: mmohammad

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 13 by ClusterFuzz, Jul 19 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4684721900748800

Fuzzer: libfuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegGlue::OpenContext
  Run
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96NQSCKG9KlgRdyBR3L4p2X5lxuSR1Z1tzgMNNUPMMsmw0cjoEPM1D2NNd0wC5YJLYROLRApx2hge64h9MHzRvQ_CX5gi6YkjU0TKq0s5tMuB5p_qM3sxO-SPnNBzNGk3q-yHxQ9P-ve7Sxy5l2zWKv9N8YKg?testcase_id=4684721900748800


Filer: mummareddy

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Status: Assigned (was: Available)
Project Member

Comment 15 by ClusterFuzz, Jul 29 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5830878869848064

Fuzzer: libfuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegGlue::OpenContext
  Run
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95kgMSWQOPQgE-9CkCDKboGhdXxOgi78DogBGFzY9eXDQ1dCnIU9QEFTgPldaT-75yqwDlafaZDZteyZ0X7bYCS-HaRGuXbimoKC0fYSYSwS3567JvwAj4okSmG_6nNxLnUuPw7d1a8defz5G5cfF2cb2Qtww?testcase_id=5830878869848064


Filer: mmohammad

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 16 by ClusterFuzz, Sep 19 2016

Labels: Stability-AFL
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4853748600143872

Fuzzer: afl_media_pipeline_integration_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  media::FFmpegGlue::OpenContext
  void base::internal::ReturnAsParamAdapter<bool>
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=402185:402404

Minimized Testcase (0.00 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv96uOkliM12plxr25FiCGq-IP-SjUCHp36cHHw9T1yZrL48eCRwsReDdwpZKr_ULEMBO2txJ81q4Uuilxg8dPfbnProtU5CM5qkUQcOERfWvbEQWSUfWJZhyy9ZnQ4Kq6GtEa9qDvbKrG5KStCT7xKGFBwr-gg?testcase_id=4853748600143872
S


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 17 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 18 by ClusterFuzz, Dec 22 2016

Status: WontFix (was: Assigned)
ClusterFuzz testcase 4684721900748800 is flaky and no longer reproduces, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment