New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 666612 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Undefined-shift in WebRtcSpl_LevinsonDurbin

Project Member Reported by ClusterFuzz, Nov 18 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5029803368644608

Fuzzer: libfuzzer_neteq_rtp_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  WebRtcSpl_LevinsonDurbin
  webrtc::Expand::AnalyzeSignal
  webrtc::Expand::Process
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=432467:432520

Minimized Testcase (0.06 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95MDESfqjjwAsn6SoJ0EqkihQN58akZA9vbZR91FoYPM0b-yxg1MPbIECrvCKpNP1UQ5_KR47ljHm-GDzq00g84aUAYXjTkAT9OBNT8S-sr4Rru-8GLdVhQWNgzd3vjc4LY993iYE2ALeumNQE5PhsZ2jYLzg?testcase_id=5029803368644608

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 

Comment 1 by ajha@chromium.org, Nov 18 2016

Components: Blink>WebRTC
Labels: M-56
Project Member

Comment 2 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 3 by guidou@chromium.org, Nov 28 2016

Components: -Blink>WebRTC Blink>WebRTC>Audio

Comment 4 by guidou@chromium.org, Nov 28 2016

Owner: hlundin@chromium.org
hlundin@: can you take a look?

Comment 5 by guidou@chromium.org, Nov 28 2016

Status: Assigned (was: Untriaged)
Labels: -M-56 M-57
Thanks. Will take a look.
Cc: tlegrand@chromium.org hlundin@chromium.org kwiberg@chromium.org
Owner: ivoc@chromium.org
Project Member

Comment 8 by bugdroid1@chromium.org, Dec 14 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/external/webrtc.git/+/7b2516620cebe50cf0cf255219794e46b82f8dbd

commit 7b2516620cebe50cf0cf255219794e46b82f8dbd
Author: ivoc <ivoc@webrtc.org>
Date: Wed Dec 14 09:59:59 2016

Fix for left shift of negative value in NetEq.

BUG= chromium:666612 

Review-Url: https://codereview.webrtc.org/2569193002
Cr-Commit-Position: refs/heads/master@{#15596}

[modify] https://crrev.com/7b2516620cebe50cf0cf255219794e46b82f8dbd/webrtc/common_audio/signal_processing/levinson_durbin.c

Project Member

Comment 9 by bugdroid1@chromium.org, Dec 14 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/external/webrtc.git/+/7b2516620cebe50cf0cf255219794e46b82f8dbd

commit 7b2516620cebe50cf0cf255219794e46b82f8dbd
Author: ivoc <ivoc@webrtc.org>
Date: Wed Dec 14 09:59:59 2016

Fix for left shift of negative value in NetEq.

BUG= chromium:666612 

Review-Url: https://codereview.webrtc.org/2569193002
Cr-Commit-Position: refs/heads/master@{#15596}

[modify] https://crrev.com/7b2516620cebe50cf0cf255219794e46b82f8dbd/webrtc/common_audio/signal_processing/levinson_durbin.c

Project Member

Comment 10 by ClusterFuzz, Dec 15 2016

ClusterFuzz has detected this issue as fixed in range 438480:438523.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5029803368644608

Fuzzer: libfuzzer_neteq_rtp_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  WebRtcSpl_LevinsonDurbin
  webrtc::Expand::AnalyzeSignal
  webrtc::Expand::Process
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=432467:432520
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=438480:438523

Minimized Testcase (0.06 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95MDESfqjjwAsn6SoJ0EqkihQN58akZA9vbZR91FoYPM0b-yxg1MPbIECrvCKpNP1UQ5_KR47ljHm-GDzq00g84aUAYXjTkAT9OBNT8S-sr4Rru-8GLdVhQWNgzd3vjc4LY993iYE2ALeumNQE5PhsZ2jYLzg?testcase_id=5029803368644608

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 11 by ClusterFuzz, Dec 15 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5029803368644608 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment