Data race in media::FFmpegDemuxer::~FFmpegDemuxer |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4781003317182464 Fuzzer: inferno_flicker Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Data race WRITE 8 Crash Address: 0x7d4c00004600 Crash State: media::FFmpegDemuxer::~FFmpegDemuxer media::WebMediaPlayerImpl::~WebMediaPlayerImpl blink::HTMLMediaElement::invokeLoadAlgorithm Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=415049:415582 Minimized Testcase (1234.38 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95iR8_jG-ia7mizHUOsjmKTxYuuMKk54Uq8slJ_vueotBuBBNTf9E2Ip4ShvMmKbzK1DPvjkm0PS4LYGlq9Hy3_YHnrK-lgQ4rxPb6RzY7exAQqmEQ8YNys8dfTeXkrROSXc7_0dDypuVsWLSoDYaWhP2zBhxqDvEw9QBl3pIynNMNyosk?testcase_id=4781003317182464 Issue manually filed by: mummareddy See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Sep 2 2016
,
Sep 2 2016
ClusterFuzz has detected this issue as fixed in range 415740:415887. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4781003317182464 Fuzzer: inferno_flicker Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Data race WRITE 8 Crash Address: 0x7d4c00004600 Crash State: media::FFmpegDemuxer::~FFmpegDemuxer media::WebMediaPlayerImpl::~WebMediaPlayerImpl blink::HTMLMediaElement::invokeLoadAlgorithm Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=415049:415582 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=415740:415887 Minimized Testcase (1234.38 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95iR8_jG-ia7mizHUOsjmKTxYuuMKk54Uq8slJ_vueotBuBBNTf9E2Ip4ShvMmKbzK1DPvjkm0PS4LYGlq9Hy3_YHnrK-lgQ4rxPb6RzY7exAQqmEQ8YNys8dfTeXkrROSXc7_0dDypuVsWLSoDYaWhP2zBhxqDvEw9QBl3pIynNMNyosk?testcase_id=4781003317182464 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 2 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Sep 3 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/a6912725c190eebf472d78a44d8fd247751e9a07 commit a6912725c190eebf472d78a44d8fd247751e9a07 Author: dalecurtis <dalecurtis@chromium.org> Date: Sat Sep 03 02:29:24 2016 Ensure FFmpegDemuxer WeakPtrs are created on the right thread. CancelPendingSeek() was called from the render thread, but the WeakFactory in FFmpegDemuxer is for use on the media thread. BUG= 643441 TEST=none Review-Url: https://codereview.chromium.org/2305923002 Cr-Commit-Position: refs/heads/master@{#416426} [modify] https://crrev.com/a6912725c190eebf472d78a44d8fd247751e9a07/media/filters/ffmpeg_demuxer.cc [modify] https://crrev.com/a6912725c190eebf472d78a44d8fd247751e9a07/media/filters/ffmpeg_demuxer.h
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||
►
Sign in to add a comment |
||||
Comment 1 by mummare...@chromium.org
, Sep 1 2016Labels: Findit-for-crash M-55 Te-Logged
Owner: dalecur...@chromium.org
Status: Assigned (was: Untriaged)