New issue
Advanced search Search tips

Issue 606710 link

Starred by 0 users

Issue metadata

Status: Duplicate
Owner:
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in media::VideoFrameCompositor::ProcessNewFrame

Project Member Reported by ClusterFuzz, Apr 26 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6072487451820032

Fuzzer: inferno_flicker
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000000002c
Crash State:
  media::VideoFrameCompositor::ProcessNewFrame
  media::VideoFrameCompositor::CallRender
  media::VideoFrameCompositor::OnRendererStateUpdate
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=389540:389622

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97bVxXoAfHMVdrDEacfcGAzPa2JXS17zOf4yrkF4kb4SVp2UmIF6HiXZPWBWarTM_UKaK_7IBJfR9TVEenvcwHFkEE1pt7YerjvaiXtPVLuu1UaVgDYTAMKyugbMqiT7oSCtax75EsQvJRigt0iHkmmwm5HYxVey101Z-0F3ggZOi-ozrI


Filer: kavvaru

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink>Media>Video Tools>Test>FindIt>CorrectResult
Labels: Te-Logged M-52
Owner: danakj@chromium.org
Status: Assigned (was: Available)
Find it tool information
========================
No CL in the regression range changes the crashed files. The result is the blame information.

Author: danakj
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/adb045fd004834946c39bc11c24399ac4ebbac7c
Time: Mon Oct 20 17:12:40 2014
The CL last changed line 46 of file size.h, which is stack frame 0.

Author: ben@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/b5e2d78a9e113b6dcb9a2e48107edd645a448c7b
Time: Wed Dec 18 21:01:15 2013
The CL last changed line 77 of file size.h, which is stack frame 1.

Author: ben@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/b5e2d78a9e113b6dcb9a2e48107edd645a448c7b
Time: Wed Dec 18 21:01:15 2013
The CL last changed line 81 of file size.h, which is stack frame 2.

Author: scherkus@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/dd061e1b8b0c9445398156eb953159362fb993a3
Time: Tue May 06 19:21:22 2014
The CL last changed line 197 of file video_frame_compositor.cc, which is stack frame 3.

Author: dalecurtis
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3e8bda613486ae81f53428ab9f41a7dbb7f9f0c3
Time: Tue May 05 07:23:15 2015
The CL last changed line 239 of file video_frame_compositor.cc, which is stack frame 4.

Author: jbauman
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/0e9c64c2f69e105042297f39a299a897c2d15459
Time: Sat Aug 15 02:58:08 2015
The CL last changed line 213 of file video_frame_compositor.cc, which is stack frame 5.

Author: dalecurtis
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3e8bda613486ae81f53428ab9f41a7dbb7f9f0c3
Time: Tue May 05 07:23:15 2015
The CL last changed line 62 of file video_frame_compositor.cc, which is stack frame 6.

Suspected Project: chromium
==========================

From the above tool information changes to the file "size.h" frame 0 is more related to this issue.Hence assigning

danakj@ Could you please look into this issue if it is related to your change,else please route this to an appropriate dev person.

Thanks, 

Comment 2 by danakj@chromium.org, Apr 28 2016

Cc: xhw...@chromium.org
Owner: dalecur...@chromium.org
My change is "gfx:: De-templatize Size and SizeF." Need to go back further, there's a null VideoFrame or something with a Size on it I guess.

=> media owners
Mergedinto: 606733
Status: Duplicate (was: Assigned)
Project Member

Comment 4 by ClusterFuzz, Apr 28 2016

ClusterFuzz has detected this issue as fixed in range 389884:390115.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6072487451820032

Fuzzer: inferno_flicker
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000000002c
Crash State:
  media::VideoFrameCompositor::ProcessNewFrame
  media::VideoFrameCompositor::CallRender
  media::VideoFrameCompositor::OnRendererStateUpdate
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=389540:389622
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=389884:390115

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97bVxXoAfHMVdrDEacfcGAzPa2JXS17zOf4yrkF4kb4SVp2UmIF6HiXZPWBWarTM_UKaK_7IBJfR9TVEenvcwHFkEE1pt7YerjvaiXtPVLuu1UaVgDYTAMKyugbMqiT7oSCtax75EsQvJRigt0iHkmmwm5HYxVey101Z-0F3ggZOi-ozrI


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment