New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 622028 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jun 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: ----
Type: Bug-Security



Sign in to add a comment

Crash in libpulsecommon-4.0.so

Project Member Reported by ClusterFuzz, Jun 21 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6013750452944896

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x9e0ff004
Crash State:
  libpulsecommon-4.0.so
  
Recommended Security Severity: Medium


Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96_jB1xBe4lkJMkE4mq1KGHDlTf7H1p2urpg8MiFY1XFkNOnHTDQR0p53hZQsmWAAqY67pO7kOH4LSB5GOeusObNM7lZTdtr1naFZHo0j-twzXpdj0spjRULQnDbLCcKSrysV-IQhXQYVbr2WUJGbnGOGEQfh0M871MyxXogRDQYQF4kL4?testcase_id=6013750452944896


Filer: tanin

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by ta...@google.com, Jun 21 2016

Owner: dalecur...@chromium.org
This happened 19,684 times already. Please take a look. Thanks!

Hmm, I'm not sure what I can do with this. It's a crash in a system library with no trace information. It's arm + pulse too, which we have no shipping users of AFAIK.
(ChromeOS uses CrAS instead of Pulse and Android use OpenSLES instead of Pulse)

Comment 4 by aarya@google.com, Jun 21 2016

Dale, any setup instructions you can give us so that on our bots, we can switch chrome to using CrAS instead of libpulse ?
Cc: dgreid@chromium.org warx@chromium.org
Are you building chromeos=1 ? issue 621129 has some details from someone who recently tried building this path.

Comment 6 by aarya@google.com, Jun 21 2016

We have both chromeos=1 asan buildbot and regular one without it. So, we need to use "use_cras" on regular buildbot without needing chromeos=1 

Comment 7 by och...@chromium.org, Jun 21 2016

Since there's no reproducible testcase (despite CF marking it as so at first), I'm going to mark this as WontFix, although it's still possible that some pulseaudio backend change could've caused this right? It seems hard to track down when this started happening though, we've been seeing this for a few months.

(The "arm" in the job type doesn't actually mean this is Chrome on ARM, it refers to the v8 arm simulator).

Comment 8 by och...@chromium.org, Jun 21 2016

Status: WontFix (was: Available)

Comment 9 by ta...@google.com, Jun 22 2016

This crash shows up again today. https://cluster-fuzz.appspot.com/testcase?key=5989409598210048

Comment 10 by ta...@google.com, Sep 13 2016

 Issue 646206  has been merged into this issue.

Comment 11 by ta...@google.com, Sep 13 2016

 Issue 646408  has been merged into this issue.

Comment 12 by ta...@google.com, Sep 13 2016

Cc: ta...@google.com
 Issue 646639  has been merged into this issue.
Project Member

Comment 13 by sheriffbot@chromium.org, Sep 28 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 14 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 15 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment