Issue metadata
Sign in to add a comment
|
Crash in CreateEvent |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6748272930848768 Fuzzer: libfuzzer_es_parser_adts_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: CreateEvent media::MediaLog::AddLogEvent media::LogHelper::~LogHelper Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=421885:421962 Minimized Testcase (1.65 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97E-vJP9JWyC8gfWXMROUr-V6J1dt-flLCCxTJWdbXfRj-o3Y1Fe2m2TXDkd68CG2O5IKTnD1TLWG0aN0emr1oXSNB4u43sJXzVSMWJKKfXQ0AKdcEbZCw6yfFXAMkCJBbLve_AXhIlEWOdgo-KyA1BAMaSsA?testcase_id=6748272930848768 Issue manually filed by: brajkumar See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Sep 30 2016
,
Sep 30 2016
Hmm, strange, will try to look at this today but am heading OOO soon, so may not get to it. +chcunningham in case I don't. This appears to be a crash in a DCHECK(), but this is odd since we explicitly check if media_log() is valid before running this DCHECK().
,
Sep 30 2016
https://codereview.chromium.org/2388443002 fix here, there's a 2nd media_log usage I didn't protect.
,
Sep 30 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/c27e432072ef22112251bbe874c8a1060a0c7ca5 commit c27e432072ef22112251bbe874c8a1060a0c7ca5 Author: dalecurtis <dalecurtis@chromium.org> Date: Fri Sep 30 19:34:39 2016 Fix media_log() crash in fuzzer tests. When called from this context, no MediaLog exists, so ensure we don't try to use it. BUG= 610848 , 650735 , 651739 TEST=libfuzzer Review-Url: https://codereview.chromium.org/2388443002 Cr-Commit-Position: refs/heads/master@{#422182} [modify] https://crrev.com/c27e432072ef22112251bbe874c8a1060a0c7ca5/media/formats/mpeg/adts_stream_parser.cc
,
Sep 30 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6748272930848768 Fuzzer: libfuzzer_es_parser_adts_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: CreateEvent media::MediaLog::AddLogEvent media::LogHelper::~LogHelper Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=421885:421962 Minimized Testcase (1.65 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97E-vJP9JWyC8gfWXMROUr-V6J1dt-flLCCxTJWdbXfRj-o3Y1Fe2m2TXDkd68CG2O5IKTnD1TLWG0aN0emr1oXSNB4u43sJXzVSMWJKKfXQ0AKdcEbZCw6yfFXAMkCJBbLve_AXhIlEWOdgo-KyA1BAMaSsA?testcase_id=6748272930848768 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Sep 30 2016
,
Oct 1 2016
ClusterFuzz has detected this issue as fixed in range 422130:422214. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6748272930848768 Fuzzer: libfuzzer_es_parser_adts_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: CreateEvent media::MediaLog::AddLogEvent media::LogHelper::~LogHelper Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=421885:421962 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=422130:422214 Minimized Testcase (1.65 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97E-vJP9JWyC8gfWXMROUr-V6J1dt-flLCCxTJWdbXfRj-o3Y1Fe2m2TXDkd68CG2O5IKTnD1TLWG0aN0emr1oXSNB4u43sJXzVSMWJKKfXQ0AKdcEbZCw6yfFXAMkCJBbLve_AXhIlEWOdgo-KyA1BAMaSsA?testcase_id=6748272930848768 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by brajkumar@chromium.org
, Sep 30 2016Labels: -Type-Bug Findit-for-crash Te-Logged Type-Bug-Regression
Owner: dalecur...@chromium.org
Status: Assigned (was: Untriaged)