channel_layout == CHANNEL_LAYOUT_DISCRETE || ChannelLayoutToChannelCount(channel |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6581429464203264 Fuzzer: libfuzzer_media_pipeline_integration_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: channel_layout == CHANNEL_LAYOUT_DISCRETE || ChannelLayoutToChannelCount(channel media::AudioBuffer::AudioBuffer media::AudioBuffer::CreateBuffer Sanitizer: address (ASAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=455091:455226 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96KHaEuiEY115PxcnKtTDVLTbesKF6K0xex9BwtGjRXkjeH7COEM4aS2xd7qDky2FcIcJYVqx6JfWa1kZloahKhhTO9UPO6CMwWvnDTs-DAfh6wWZO7RDOr3SUOJmRMBSjRX0pFiREXp-8EhTVu7qXN-VJ_7UMAkiJFZLpmp205RCiDSjyEdqL3hzoOQ4lMS6Nhjbn4Smi9TwSx6wMGUyMo7UdK2Ffyy4FkeniUQX2D-M1c0aIy9SjVcNrQRPAIkAk7Apk5Vja7RREKWQtEeLhx66Om8uXh6FoEQeTxSxIFOfpBzvDBWZLQ1VEKWY9bAKxaknyWYJswVzRe0N8Zxhz0_6lk25MKi8vrBfg82h-uBGexdWo?testcase_id=6581429464203264 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Mar 8 2017
Reassigning to dalecurtis@, since this is an assert in media/base/audio_buffer.cc
,
Mar 9 2017
=>tguilbert as part of the ffmpeg roll.
,
Mar 13 2017
,
Mar 16 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/cd31831bb240ce19d3e3af6f2b95f8ad11c96e5c commit cd31831bb240ce19d3e3af6f2b95f8ad11c96e5c Author: tguilbert <tguilbert@chromium.org> Date: Thu Mar 16 01:35:03 2017 Fix unsupported audio channel layout We currently do not check the returned channel layout when converting Ffmpeg to chrome channel layouts. This means that we still try to create audio buffers whenever we have an unsupported channel layout. This causes some tests to crash when hitting a DCHECK in AudioBuffer's ctor. This CL fixes the issue by erroring out early rather than trying to create an invalid AudioBuffer. BUG= 699373 TEST=manually checked it didn't crash anymore Review-Url: https://codereview.chromium.org/2748023004 Cr-Commit-Position: refs/heads/master@{#457302} [modify] https://crrev.com/cd31831bb240ce19d3e3af6f2b95f8ad11c96e5c/media/filters/ffmpeg_audio_decoder.cc
,
Mar 16 2017
ClusterFuzz has detected this issue as fixed in range 457280:457308. Detailed report: https://clusterfuzz.com/testcase?key=6581429464203264 Fuzzer: libfuzzer_media_pipeline_integration_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: channel_layout == CHANNEL_LAYOUT_DISCRETE || ChannelLayoutToChannelCount(channel media::AudioBuffer::AudioBuffer media::AudioBuffer::CreateBuffer Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=455091:455226 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=457280:457308 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96KHaEuiEY115PxcnKtTDVLTbesKF6K0xex9BwtGjRXkjeH7COEM4aS2xd7qDky2FcIcJYVqx6JfWa1kZloahKhhTO9UPO6CMwWvnDTs-DAfh6wWZO7RDOr3SUOJmRMBSjRX0pFiREXp-8EhTVu7qXN-VJ_7UMAkiJFZLpmp205RCiDSjyEdqL3hzoOQ4lMS6Nhjbn4Smi9TwSx6wMGUyMo7UdK2Ffyy4FkeniUQX2D-M1c0aIy9SjVcNrQRPAIkAk7Apk5Vja7RREKWQtEeLhx66Om8uXh6FoEQeTxSxIFOfpBzvDBWZLQ1VEKWY9bAKxaknyWYJswVzRe0N8Zxhz0_6lk25MKi8vrBfg82h-uBGexdWo?testcase_id=6581429464203264 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 16 2017
ClusterFuzz testcase 6581429464203264 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by durga.behera@chromium.org
, Mar 8 2017Labels: Test-Predator-Wrong-CLs M-59
Owner: rtoy@chromium.org
Status: Assigned (was: Untriaged)