New issue
Advanced search Search tips

Issue 632583 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Crash in media::AudioTimestampValidator::CheckForTimestampGap

Project Member Reported by ClusterFuzz, Jul 29 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5167049798320128

Fuzzer: media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x03e90000013f
Crash State:
  media::AudioTimestampValidator::CheckForTimestampGap
  media::DecoderStreamTraits<
  media::DecoderStream<
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=408389:408457

Minimized Testcase (0.60 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97eDURks_S-Lb2ZpOidV9n4qwdLiUUBrxIl122LKV61NzSJXqcsDFPvMdrwhE3qTC-31rujPKDw-0K2inzPzfAYU94EymWmchvU_1b-76B7LQ9pkcUgUcKNi5iMBKfQ59L6AdlE8D-O2nYYkBhNa33UsPlIpA?testcase_id=5167049798320128

Filer: rnimmagadda

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Labels: -Pri-1 -Type-Bug M-54 Findit-for-crash Te-Logged Pri-2 Type-Bug-Regression
Owner: dalecur...@chromium.org
Status: Assigned (was: Untriaged)
Suspecting:

Author: dalecurtis
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/39a7f93d67f79d6afadb0f74254eef19b5ff9318
Time: Tue Jul 19 18:34:59 2016
The CL last changed line 45 of file audio_timestamp_validator.cc, which is stack frame 3.

@dalecurtis: Could you please look into this issue.

Thank you.
Cc: dalecur...@chromium.org
Owner: chcunningham@chromium.org
Looks like it's complaining about the new timestamp validator, but likely ffmpeg is outputing something gnarly.
I think both this and  Issue 628521  are essentially the same... content played with either negative timestamps or no timestamp tripping up DCHECKs. 

One route here would be to replace the DCHECKs in ffmpeg_demuxer with decode errors... WDYT?
Project Member

Comment 4 by ClusterFuzz, Aug 1 2016

ClusterFuzz has detected this issue as fixed in range 408588:408608.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5167049798320128

Fuzzer: media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x03e90000013f
Crash State:
  media::AudioTimestampValidator::CheckForTimestampGap
  media::DecoderStreamTraits<
  media::DecoderStream<
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=408389:408457
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=408588:408608

Minimized Testcase (0.60 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97eDURks_S-Lb2ZpOidV9n4qwdLiUUBrxIl122LKV61NzSJXqcsDFPvMdrwhE3qTC-31rujPKDw-0K2inzPzfAYU94EymWmchvU_1b-76B7LQ9pkcUgUcKNi5iMBKfQ59L6AdlE8D-O2nYYkBhNa33UsPlIpA?testcase_id=5167049798320128

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Aug 1 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Status: Assigned (was: Verified)
No changes from me yet - "fixed" seems unlikely.
Dale, see comment #3
Project Member

Comment 8 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 9 by mmoroz@chromium.org, Oct 24 2017

For more information, please see https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md.

The link referenced in the description is no longer valid.

(bulk edit)

Sign in to add a comment