New issue
Advanced search Search tips

Issue 698549 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Mar 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in base::debug::DebugBreak

Project Member Reported by ClusterFuzz, Mar 5 2017

Issue description

Components: Blink>Media
Labels: Test-Predator-Wrong M-59
Owner: dalecur...@chromium.org
Status: Assigned (was: Untriaged)
Based on recent change made to file "ffmpeg_demuxer.cc" suspecting below.

Review-Url: https://codereview.chromium.org/2710133003
dalecurtis@: Could you please take a look into this if its related to your change.
Interesting. Probably unrelated to that change, but should be handled -- will put out a fix shortly.
FWIW, this condition is handled, so the DCHECKs should just be removed.
Project Member

Comment 4 by bugdroid1@chromium.org, Mar 7 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/86a0024f06be519a8dc10ce7d2fc6eea5971645f

commit 86a0024f06be519a8dc10ce7d2fc6eea5971645f
Author: dalecurtis <dalecurtis@chromium.org>
Date: Tue Mar 07 18:46:24 2017

Remove FFmpegDemuxer DCHECKs that are handled via conditionals.

These are tripping up the fuzzer tests, so remove. Per the style
guide we should not have DCHECKs which we handle too.

BUG= 698549 
TEST=none

Review-Url: https://codereview.chromium.org/2736643003
Cr-Commit-Position: refs/heads/master@{#455156}

[modify] https://crrev.com/86a0024f06be519a8dc10ce7d2fc6eea5971645f/media/filters/ffmpeg_demuxer.cc

Project Member

Comment 5 by ClusterFuzz, Mar 8 2017

ClusterFuzz has detected this issue as fixed in range 455091:455226.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5781477813125120

Fuzzer: libfuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x03e9000071e8
Crash State:
  base::debug::DebugBreak
  media::FFmpegDemuxer::OnReadFrameDone
  void base::internal::FunctorTraits<void
  
Sanitizer: address (ASAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=444427:444575
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=455091:455226

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96Sn39oetEJN1nYU9bpC-Ue93x5byp9Uy1NngRQLGx2TOKMzkR48c_RjeUsyOk-V7DCDBfg2L786MiMEQqH9DyKZNxATLdFNto2067xggpGi-KCaDU1R69dPaUCrShXt2vCWv3EPXXXLsb8qusS2LIiK0wtyAd_VPqqIYVMDvAHJGt2XB-i2t5De-k0bmb6UcztHc4Pos0j98Vc9nlhogrcK2jDGOkfQRcZGaSelDQAsXPoUbZd96h9ZTJokUHRMNOwDBjh9zAajsu5GDoN1foPH9UKfjnSpr80yzaOrvmsXI-KmvsYw2qlPYFpCB6t-ExnKXKfFEOjscX0vbFQTzZLD3PkIBOYbYt4V52LxrATcUo-mNE?testcase_id=5781477813125120


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Mar 8 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5781477813125120 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment