Undefined-shift in decode_pitch_lag_high |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4999992424267776 Fuzzer: libfuzzer_media_pipeline_integration_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: decode_pitch_lag_high decode_pitch_vector amrwb_decode_frame Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=423338:423416 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94dD-gv-7EpuOSaC7Aoa489kakL4lippoyVxFfVHCMYp-M_PCEApLHCSa3aLkpASthossTOMs0BKa0N-k50U1X0pYdp8VH6sL6lKa-wEvpLdLIFBrxcWu7PYZwDkJpDsLxrTFhYPmik3yH2dTVEjT8L9s6QMzG1DtnYJOmTtit_XTMTD2MmT5FhTr72UrZ0w5HkVVkK-G66S3a4v5up6tu9y3E36x3byUdqCICdYGMTEBXuF09ZFCnanufxEAMbeW7WnZTJ_NJHkvhw519wagedGrlcjo7b9S0IITeU4c3q6RZOaJ_qDaE80-LX2ZvP9ZVRMgxADmbFv3GxXZDDI1e5GCywBJ2O_2bSL7en_rgFXoAq9Fc?testcase_id=4999992424267776 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Mar 23 2017
I dont seem to have access to the "Detailed report: https://clusterfuzz.com/testcase?key=4999992424267776", can you provide ubsan output for this issue ?
,
Mar 29 2017
,
Mar 30 2017
Emailed you (michaelni@gmx.at) the details along w/ minimized test case. Thank you!
,
Mar 31 2017
Looking at the details, this looks like the issue fixed in the commit already identified by Comment 1 by msrchandra@chromium.org, Mar 22 that is 6bd79ba59f46a8b3133f28faae53b75540469803 The details point to a shift at ../../third_party/ffmpeg/libavcodec/amrwbdec.c:265:69: runtime error: left shift of negative value -1 Theres a shift prior to 6bd79ba59f46a8b3133f28faae53b75540469803 at this position but not afterwards
,
Apr 6 2017
Marking the issue as Fixed as per comment# 5, so changing the status to Fixed. Please correct me if I am wrong. Thank You
,
Jun 7 2017
ClusterFuzz has detected this issue as fixed in range 477380:477461. Detailed report: https://clusterfuzz.com/testcase?key=4999992424267776 Fuzzer: libFuzzer_media_pipeline_integration_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: decode_pitch_lag_high decode_pitch_vector amrwb_decode_frame Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=423338:423416 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=477380:477461 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4999992424267776 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||
►
Sign in to add a comment |
|||
Comment 1 by msrchandra@chromium.org
, Mar 22 2017Labels: Test-Predator-Wrong-CLs M-59