New issue
Advanced search Search tips

Issue 608251 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: May 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in mkvmuxer::Track::set_codec_id

Project Member Reported by ClusterFuzz, May 2 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6445923751690240

Fuzzer: cpaulin_mediarecorder
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  mkvmuxer::Track::set_codec_id
  media::WebmMuxer::OnEncodedVideo
  content::MediaRecorderHandler::OnEncodedVideo
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=144946:145047

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv941DaXxzsMFKZgHjb8mo5a0pd4TiQN9BTIezzsgdqPDnVm3tTCi2B2vH9HYXl9fSOWaQm8T565hNWoH0zLzrhJikuAfa02SxaGlYB4WrxDee9oNDpd2vjPvVbnqB8k4wRU14YFKNXDDB-bM1pndtctYM8qS7w


Additional requirements: Requires HTTP

Filer: brajkumar

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Internals>Media>Codecs
Labels: findit-for-crash Te-Logged
Owner: mcasas@chromium.org
Status: Assigned (was: Available)
No CL in the regression range changes the crashed files. The result is the blame information.

Author: mcasas
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/913419cf02929813a7ca8d1584fb42fc55d5e10d
Time: Fri Apr 29 16:40:00 2016
The CL last changed line 227 of file webm_muxer.cc, which is stack frame 1.

Author: mcasas
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/a466bd2cc32a9d5bcba758473ebd993a296f7d6d
Time: Tue Aug 25 21:22:56 2015
The CL last changed line 135 of file webm_muxer.cc, which is stack frame 2.

Author: dcheng
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/07945f63b71cb1f5362f5ebf984496d49dc08299
Time: Sat Dec 26 07:59:32 2015
The CL last changed line 266 of file media_recorder_handler.cc, which is stack frame 3.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6ba91a9df7cb8e3fee614639c1ecb5af3f68f807
Time: Mon Feb 15 20:51:34 2016
The CL last changed line 181 of file bind_internal.h, which is stack frame 4.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6ba91a9df7cb8e3fee614639c1ecb5af3f68f807
Time: Mon Feb 15 20:51:34 2016
The CL last changed line 334 of file bind_internal.h, which is stack frame 5.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8ce65709225bac5922e6b2b80a912cf9796949b1
Time: Thu Feb 05 19:11:26 2015
The CL last changed line 372 of file bind_internal.h, which is stack frame 6.

Suspected Project: chromium
===============================
Above mentioned is the CL's list from findit, Suspecting the 1st file of "webm_muxer.cc" from the frame #1 .

mcasas@: Could you please look into this issue if it is related to your change, else please help us in assigning it to the right owner.

Thanks!
Project Member

Comment 2 by ClusterFuzz, May 4 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6445923751690240

Fuzzer: cpaulin_mediarecorder
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  mkvmuxer::Track::set_codec_id
  media::WebmMuxer::OnEncodedVideo
  content::MediaRecorderHandler::OnEncodedVideo
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=144946:145047

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv941DaXxzsMFKZgHjb8mo5a0pd4TiQN9BTIezzsgdqPDnVm3tTCi2B2vH9HYXl9fSOWaQm8T565hNWoH0zLzrhJikuAfa02SxaGlYB4WrxDee9oNDpd2vjPvVbnqB8k4wRU14YFKNXDDB-bM1pndtctYM8qS7w


Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, May 9 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4649927031914496

Fuzzer: cpaulin_mediarecorder
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  mkvmuxer::Track::set_codec_id
  media::WebmMuxer::OnEncodedVideo
  content::MediaRecorderHandler::OnEncodedVideo
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=172836:173286

Minimized Testcase (11.43 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97JZUgFXA4WHWsH5FsQnQJFIyA_7R792rbsp64yAEx9gdkHkEde0Ug6_-lUcgY4p5JHHMkMd637Y2B8j0WKSDAZiH1ZB1cMxljEzD4XE8d36qwD3m32nYQweuKVJp-jIeaYxTWdOhbNllPa91KTElU7O0Z6rQ

Additional requirements: Requires HTTP

Filer: rnimmagadda

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 4 by ClusterFuzz, May 10 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4649927031914496

Fuzzer: cpaulin_mediarecorder
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  mkvmuxer::Track::set_codec_id
  media::WebmMuxer::OnEncodedVideo
  content::MediaRecorderHandler::OnEncodedVideo
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=172836:173286

Minimized Testcase (11.43 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97JZUgFXA4WHWsH5FsQnQJFIyA_7R792rbsp64yAEx9gdkHkEde0Ug6_-lUcgY4p5JHHMkMd637Y2B8j0WKSDAZiH1ZB1cMxljEzD4XE8d36qwD3m32nYQweuKVJp-jIeaYxTWdOhbNllPa91KTElU7O0Z6rQ

Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, May 19 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5172549171806208

Fuzzer: ochang_domfuzzer
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  mkvmuxer::Track::set_codec_id
  media::WebmMuxer::OnEncodedVideo
  content::MediaRecorderHandler::OnEncodedVideo
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=144946:145047

Minimized Testcase (1.63 Kb): https://cluster-fuzz.appspot.com/download/AMIfv948pqMqu6N9-EZguCdXEPZloeIQacTHfkds7we3W5ka6vHpRp3nXS1uCRI2d7Q0lxYrzpeDI_sFdSjA434azepFnl6UTiUc5CShd9rp7vbZLKJB9zOqaleuqSAq8ctxcxBUdDsH1YYpsG0P29Vpj8glNxdOrw

Additional requirements: Requires HTTP

Filer: ranjitkan

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 6 by ClusterFuzz, May 25 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5172549171806208

Fuzzer: ochang_domfuzzer
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  mkvmuxer::Track::set_codec_id
  media::WebmMuxer::OnEncodedVideo
  content::MediaRecorderHandler::OnEncodedVideo
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=144946:145047

Minimized Testcase (1.63 Kb): https://cluster-fuzz.appspot.com/download/AMIfv948pqMqu6N9-EZguCdXEPZloeIQacTHfkds7we3W5ka6vHpRp3nXS1uCRI2d7Q0lxYrzpeDI_sFdSjA434azepFnl6UTiUc5CShd9rp7vbZLKJB9zOqaleuqSAq8ctxcxBUdDsH1YYpsG0P29Vpj8glNxdOrw

Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, May 26 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5458978192752640

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  mkvmuxer::Track::set_codec_id
  media::WebmMuxer::OnEncodedVideo
  content::MediaRecorderHandler::OnEncodedVideo
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=209699:209703

Minimized Testcase (2.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95J2L3-moT8NoQ6AQWs2xx35qdT7sEkba5cXb5yeF0L76Sg4oYxd6Y6tmPEHDX8skfVmsVw2sk8tf_kaUttNMhDzZpTH0o5IHXzR1xbWpMZ5bFsmIcLNv3mPnRBrvzjITjckR1Rya_BKq90gA8gqHr0jg8A7w

Additional requirements: Requires HTTP

Filer: manoranjanr

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 8 by ClusterFuzz, May 27 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5458978192752640

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  mkvmuxer::Track::set_codec_id
  media::WebmMuxer::OnEncodedVideo
  content::MediaRecorderHandler::OnEncodedVideo
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=209699:209703

Minimized Testcase (2.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95J2L3-moT8NoQ6AQWs2xx35qdT7sEkba5cXb5yeF0L76Sg4oYxd6Y6tmPEHDX8skfVmsVw2sk8tf_kaUttNMhDzZpTH0o5IHXzR1xbWpMZ5bFsmIcLNv3mPnRBrvzjITjckR1Rya_BKq90gA8gqHr0jg8A7w

Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Status: WontFix (was: Assigned)
Marking 'WontFix' as per c#8.

Thank you!
Project Member

Comment 10 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment