New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 770588 link

Starred by 1 user

Issue metadata

Status: Fixed
Merged: issue 767336
Owner:
Closed: Aug 13
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Mac
Pri: 1
Type: Bug



Sign in to add a comment

Out-of-memory in media_pipeline_integration_fuzzer

Project Member Reported by ClusterFuzz, Oct 2 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5005845627928576

Fuzzer: libFuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  media_pipeline_integration_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=413228:413328

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5005845627928576

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Oct 2 2017

Labels: OS-Mac
Cc: msrchandra@chromium.org pnangunoori@chromium.org
Components: Blink>Media
Labels: M-61 Test-Predator-Wrong
Owner: xhw...@chromium.org
Status: Assigned (was: Untriaged)
As per the  Issue 729900  owner, assigning this issue to @xhwang.
@xhwang -- Could you please look into this issue, kindly reassign if it has nothing to do with your changes.
Thanks.
Mergedinto: 767336
Status: Duplicate (was: Assigned)
Can't repro, so guessing this is related to histogram oom.
Cc: dalecur...@chromium.org
Status: Assigned (was: Duplicate)
Unduping this one since it doesn't seem improved by my CL.

Comment 5 by xhw...@chromium.org, Oct 12 2017

dalecurtis: I won't have time looking into this any time soon, and this is not specific to EME. Is it possible to find another owner for a quicker fix? Thanks!
Cc: xhw...@chromium.org
Owner: hubbe@chromium.org
=>randomly assigned to hubbe@ - we've got enough of these for everyone to have one :)

Comment 7 by mmoroz@chromium.org, Oct 24 2017

For more information, please see https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md.

The link referenced in the description is no longer valid.
Blocking: 77755
Blocking: -77755 777555
Blocking: -777555
Patch didn't seem to resolve the OOM crash (CF stats still show it occurring 10s of times daily). Removing from being a ffmpeg roll blocker.
Components: -Blink>Media Internals>Media>Codecs
Owner: tguilbert@chromium.org
=>tguilbert as part of next ffmpeg roll.
Project Member

Comment 14 by ClusterFuzz, Aug 5

ClusterFuzz has detected this issue as fixed in range 517703:517713.

Detailed report: https://clusterfuzz.com/testcase?key=5005845627928576

Fuzzer: libFuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  media_pipeline_integration_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=413228:413328
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=517703:517713

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5005845627928576

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
I'm not sure why this could have been fixed. Rerunning task.
Project Member

Comment 16 by ClusterFuzz, Aug 11

ClusterFuzz has detected this issue as fixed in range 517703:517713.

Detailed report: https://clusterfuzz.com/testcase?key=5005845627928576

Fuzzer: libFuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  media_pipeline_integration_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=413228:413328
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=517703:517713

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5005845627928576

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Status: Fixed (was: Assigned)
I'm not sure how this was fixed, but it seems it was. The fixed range includes this CL:
https://chromium.googlesource.com/chromium/src/+/aea3d2d4d8d304df1a029ef83d248508073bd066

Sign in to add a comment