frames <= frames_ in audio_buffer_queue.cc |
||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6532381578362880 Fuzzer: inferno_flicker Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: frames <= frames_ in audio_buffer_queue.cc media::AudioBufferQueue::SeekFrames media::AudioRendererAlgorithm::FillBuffer Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=326266:326287 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94l-_yCWf6ZvgfTUeeuh4dgWHXla9F_YAn07Tt_uZO-fMRU-UJEVrQY8CZjtcxWFijAWAe-T7MZ01NbGMOh8P2JWVlI5NVy_XuhxCFxETc6nF26oCgl1S4hmBCdQdMmbHzfxzLL4iCh48o4_QeFlliig8mttdagtnOkkHDzxX1Ns2DBMAk?testcase_id=6532381578362880 Filer: mummareddy See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jun 22 2016
ccing few more dev who made recent changes to audio_buffer_queue.cc
,
Jun 22 2016
,
Jun 22 2016
Moving this nonessential bug to the next milestone. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 22 2016
I think the most likely suspect in that CL range is https://codereview.chromium.org/1094783002 a.berwal@ could you take a look please?
,
Jun 27 2016
,
Jul 3 2016
This issue is Pri-1 but has already been moved once. Lowering the priority and moving to the next milestone. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 7 2016
In AudioRendererAlgorithm::FillBuffer (at https://cs.chromium.org/chromium/src/media/filters/audio_renderer_algorithm.cc?l=163) seek_frames might be audio_buffer_.frames() + 1 in case muted_partial_frame_ is incremented by audio_buffer_.frames() and muted_partial_frame_ is very close to 1 beforehand. Then, the incrementation of muted_partial_frame_ might be rounded up. I suggest checking if seek_frames is larger than audio_buffer_.frame() and in this case decrease frames_to_render and retry. Should I make a CL?
,
Jul 7 2016
whoops, somehow this got missed from my queue. Yes, please make a CL, thanks! Otherwise assign back to me and I'll find someone.
,
Jul 8 2016
,
Jul 13 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/4b4d410a51e381550a06eed06eed502a69ef1508 commit 4b4d410a51e381550a06eed06eed502a69ef1508 Author: maxmorin <maxmorin@chromium.org> Date: Wed Jul 13 07:05:43 2016 Check for bad floating point rounding in audio_renderer_algorithm. BUG= 622125 Review-Url: https://codereview.chromium.org/2127413002 Cr-Commit-Position: refs/heads/master@{#405062} [modify] https://crrev.com/4b4d410a51e381550a06eed06eed502a69ef1508/media/filters/audio_renderer_algorithm.cc
,
Jul 13 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/4b4d410a51e381550a06eed06eed502a69ef1508 commit 4b4d410a51e381550a06eed06eed502a69ef1508 Author: maxmorin <maxmorin@chromium.org> Date: Wed Jul 13 07:05:43 2016 Check for bad floating point rounding in audio_renderer_algorithm. BUG= 622125 Review-Url: https://codereview.chromium.org/2127413002 Cr-Commit-Position: refs/heads/master@{#405062} [modify] https://crrev.com/4b4d410a51e381550a06eed06eed502a69ef1508/media/filters/audio_renderer_algorithm.cc
,
Jul 14 2016
ClusterFuzz has detected this issue as fixed in range 405052:405102. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6532381578362880 Fuzzer: inferno_flicker Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: frames <= frames_ in audio_buffer_queue.cc media::AudioBufferQueue::SeekFrames media::AudioRendererAlgorithm::FillBuffer Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=326266:326287 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=405052:405102 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94l-_yCWf6ZvgfTUeeuh4dgWHXla9F_YAn07Tt_uZO-fMRU-UJEVrQY8CZjtcxWFijAWAe-T7MZ01NbGMOh8P2JWVlI5NVy_XuhxCFxETc6nF26oCgl1S4hmBCdQdMmbHzfxzLL4iCh48o4_QeFlliig8mttdagtnOkkHDzxX1Ns2DBMAk?testcase_id=6532381578362880 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 14 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||||||||
►
Sign in to add a comment |
||||||||||||
Comment 1 by mummare...@chromium.org
, Jun 22 2016Labels: Te-Logged M-52