Out-of-memory in mediasource_MP4_AVC1_pipeline_integration_fuzzer |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4806638619066368 Fuzzer: libFuzzer_mediasource_MP4_AVC1_pipeline_integration_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: Out-of-memory (exceeds 2048 MB) Crash Address: Crash State: mediasource_MP4_AVC1_pipeline_integration_fuzzer Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=497063:497144 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4806638619066368 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Oct 24 2017
For more information, please see https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md. The link referenced in the description is no longer valid.
,
Oct 24 2017
,
Oct 24 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/91965df34bca6d9236e62c7a228354d17843dcfa commit 91965df34bca6d9236e62c7a228354d17843dcfa Author: Dan Sanders <sandersd@chromium.org> Date: Tue Oct 24 23:29:56 2017 Limit TrackRunInfo.samples allocation size to 150MB. When trun.sample_count is large, TrackRunInfo.samples may be allocated larger than available memory. This CL caps that allocation to 150MB, and removes the earlier limit that disallowed two (or more) zero-sized samples in a row. This effectively limits the number of samples per trun to 6.5M, which also helps avoid timeouts in fuzzing. That problem is unlikely to be solved by this CL alone, though. Bug: 776721 , 776246 , 774760 , 776018 , 770577 Cq-Include-Trybots: master.tryserver.chromium.android:android_optional_gpu_tests_rel;master.tryserver.chromium.linux:linux_optional_gpu_tests_rel;master.tryserver.chromium.mac:mac_optional_gpu_tests_rel;master.tryserver.chromium.win:win_optional_gpu_tests_rel Change-Id: Ib4c35c066193a9da8ef460d9d9283e999d803ced Reviewed-on: https://chromium-review.googlesource.com/734702 Commit-Queue: Dan Sanders <sandersd@chromium.org> Reviewed-by: Dale Curtis <dalecurtis@chromium.org> Reviewed-by: Matthew Wolenetz <wolenetz@chromium.org> Cr-Commit-Position: refs/heads/master@{#511301} [modify] https://crrev.com/91965df34bca6d9236e62c7a228354d17843dcfa/media/formats/mp4/track_run_iterator.cc
,
Oct 25 2017
ClusterFuzz has detected this issue as fixed in range 511297:511318. Detailed report: https://clusterfuzz.com/testcase?key=4806638619066368 Fuzzer: libFuzzer_mediasource_MP4_AVC1_pipeline_integration_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: Out-of-memory (exceeds 2048 MB) Crash Address: Crash State: mediasource_MP4_AVC1_pipeline_integration_fuzzer Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=497063:497144 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=511297:511318 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4806638619066368 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 25 2017
ClusterFuzz testcase 4806638619066368 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by pnangunoori@chromium.org
, Oct 23 2017Components: Blink>Media
Labels: M-62 Test-Predator-Wrong
Owner: sande...@chromium.org
Status: Assigned (was: Untriaged)