New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 840115 link

Starred by 3 users

Issue metadata

Status: Verified
Owner:
Last visit 19 days ago
Closed: Jul 18
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Timeout in audio_decoder_isacfix_fuzzer

Project Member Reported by ClusterFuzz, May 5 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5851238621773824

Fuzzer: libFuzzer_audio_decoder_isacfix_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Timeout (exceeds 25 secs)
Crash Address: 
Crash State:
  audio_decoder_isacfix_fuzzer
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=551565:551569

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5851238621773824

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, May 5 2018

Cc: kwiberg@webrtc.org mflodman@webrtc.org henrika@webrtc.org
Labels: ClusterFuzz-Auto-CC
Automatically adding ccs based on OWNERS file / target commit history.

If this is incorrect, please add ClusterFuzz-Wrong label.
Owner: hlundin@chromium.org
Status: Assigned (was: Untriaged)
Project Member

Comment 3 by bugdroid1@chromium.org, Jul 5

The following revision refers to this bug:
  https://webrtc.googlesource.com/src.git/+/0f5dc8b5f33653f5827ceebd5aea9cc53ed5508f

commit 0f5dc8b5f33653f5827ceebd5aea9cc53ed5508f
Author: Henrik Lundin <henrik.lundin@webrtc.org>
Date: Thu Jul 05 14:30:12 2018

Limit input size to iSAC and iLBC decoder fuzzers

The size limit is set to correspond to approximately 5 seconds of
decoded audio at the codecs' normal operating bitrates. This is to
avoid timeouts on the bots.

NOTRY=true

Bug:  chromium:840115 
Change-Id: I74b3c196259e03981aa2c4ef349e6e1334e9bf58
Reviewed-on: https://webrtc-review.googlesource.com/87302
Reviewed-by: Sam Zackrisson <saza@webrtc.org>
Commit-Queue: Henrik Lundin <henrik.lundin@webrtc.org>
Cr-Commit-Position: refs/heads/master@{#23857}
[modify] https://crrev.com/0f5dc8b5f33653f5827ceebd5aea9cc53ed5508f/test/fuzzers/BUILD.gn

Project Member

Comment 4 by bugdroid1@chromium.org, Jul 5

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/46c1bb5ef7601a23f4610314f172232c59fb1b32

commit 46c1bb5ef7601a23f4610314f172232c59fb1b32
Author: webrtc-chromium-autoroll <webrtc-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com>
Date: Thu Jul 05 20:59:02 2018

Roll src/third_party/webrtc c480e9d7a86d..f91d70bc25bc (7 commits)

https://webrtc.googlesource.com/src.git/+log/c480e9d7a86d..f91d70bc25bc


git log c480e9d7a86d..f91d70bc25bc --date=short --no-merges --format='%ad %ae %s'
2018-07-05 buildbot@webrtc.org Roll chromium_revision 39b1860428..b2695df06e (572705:572823)
2018-07-05 saza@webrtc.org Create separate build targets for utility/ in APM
2018-07-05 alessiob@webrtc.org Revert "Reland "Unit test for case where the number of active and configured spatial""
2018-07-05 gustaf@webrtc.org AEC3: Slower adaptation of main filter
2018-07-05 henrik.lundin@webrtc.org Limit input size to iSAC and iLBC decoder fuzzers
2018-07-05 philipel@webrtc.org Add accessors to the types in the RTPVideoTypeHeader in RTPVideoHeader.
2018-07-05 philipel@webrtc.org Remove RTPTypeHeader union and use RTPVideoHeader directly.


Created with:
  gclient setdep -r src/third_party/webrtc@f91d70bc25bc

The AutoRoll server is located here: https://webrtc-chromium-roll.skia.org

Documentation for the AutoRoller is here:
https://skia.googlesource.com/buildbot/+/master/autoroll/README.md

If the roll is causing failures, please contact the current sheriff, who should
be CC'd on the roll, and stop the roller if necessary.

CQ_INCLUDE_TRYBOTS=luci.chromium.try:linux_chromium_archive_rel_ng;master.tryserver.chromium.mac:mac_chromium_archive_rel_ng

BUG=chromium:None,chromium:840115,chromium:none,chromium:none
TBR=webrtc-chromium-sheriffs-robots@google.com

Change-Id: I01268b6c9764ef208f8557081619d92259e5b55c
Reviewed-on: https://chromium-review.googlesource.com/1127381
Reviewed-by: webrtc-chromium-autoroll <webrtc-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com>
Commit-Queue: webrtc-chromium-autoroll <webrtc-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com>
Cr-Commit-Position: refs/heads/master@{#572853}
[modify] https://crrev.com/46c1bb5ef7601a23f4610314f172232c59fb1b32/DEPS

Status: Fixed (was: Assigned)
Project Member

Comment 6 by ClusterFuzz, Jul 13

Labels: Needs-Feedback
ClusterFuzz testcase 5851238621773824 is still reproducing on tip-of-tree build (trunk).

Please re-test your fix against this testcase and if the fix was incorrect or incomplete, please re-open the bug. Otherwise, ignore this notification and add ClusterFuzz-Wrong label.
Cc: hlundin@chromium.org
Owner: saza@chromium.org
Status: Assigned (was: Fixed)
Components: Blink>WebRTC>Audio
Status: Started (was: Assigned)
Project Member

Comment 10 by bugdroid1@chromium.org, Jul 17

The following revision refers to this bug:
  https://webrtc.googlesource.com/src.git/+/35c773dad6f602e38e87aba0b693292fa868629b

commit 35c773dad6f602e38e87aba0b693292fa868629b
Author: Sam Zackrisson <saza@webrtc.org>
Date: Tue Jul 17 09:14:45 2018

Cap the number of fuzzed decoder packets to 200

The fuzzer figured out that 3 bytes is enough to fuzz a package.
2 bytes for packet length, and 1 byte of actual packet. A 20K test case
can generate > 6000 packets. It does not seem like efficient fuzzing.

This CL simply stops execution when 200 packets have been generated.
That corresponds to 4 seconds of 20 ms packets.

Bug:  chromium:840115 
Change-Id: Id2742a6f8021134bacd8a6e8c71b32f20c7f1086
Reviewed-on: https://webrtc-review.googlesource.com/88566
Reviewed-by: Alex Loiko <aleloi@webrtc.org>
Commit-Queue: Sam Zackrisson <saza@webrtc.org>
Cr-Commit-Position: refs/heads/master@{#24000}
[modify] https://crrev.com/35c773dad6f602e38e87aba0b693292fa868629b/test/fuzzers/audio_decoder_fuzzer.cc

Project Member

Comment 11 by bugdroid1@chromium.org, Jul 17

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/c3323af925e5d404bc1371f22a45e61c5abeb7e7

commit c3323af925e5d404bc1371f22a45e61c5abeb7e7
Author: webrtc-chromium-autoroll <webrtc-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com>
Date: Tue Jul 17 23:20:24 2018

Roll src/third_party/webrtc 4597e0c46fc5..dbdb3a00797d (15 commits)

https://webrtc.googlesource.com/src.git/+log/4597e0c46fc5..dbdb3a00797d


git log 4597e0c46fc5..dbdb3a00797d --date=short --no-merges --format='%ad %ae %s'
2018-07-17 stefan@webrtc.org Refactoring PayloadRouter.
2018-07-17 yinwa@webrtc.org Implement congestion window direct pushback to encoders. (Without TaskQueue)
2018-07-17 buildbot@webrtc.org Roll chromium_revision c09887405b..9ec8cfdbc9 (575517:575625)
2018-07-17 sakal@webrtc.org Update CameraCapturer to use the new CapturerObserver.
2018-07-17 ilnik@webrtc.org Revert "Enable simulcast screenshare by default"
2018-07-17 oprypin@webrtc.org Replace accidental usages of source_set with rtc_source_set
2018-07-17 ilnik@webrtc.org Enable simulcast screenshare by default
2018-07-17 mbonadei@webrtc.org Enabling clang::find_bad_constructs for common_audio.
2018-07-17 aleloi@webrtc.org Fuzz more kinds of floats in the APM fuzzer.
2018-07-17 saza@webrtc.org Cap the number of fuzzed decoder packets to 200
2018-07-17 aleloi@webrtc.org Division by zero in RNN-VAD.
2018-07-17 mbonadei@webrtc.org Enabling clang:find_bad_constructs from modules/utility.
2018-07-17 mbonadei@webrtc.org Enabling clang::find_bad_constructs for AEC3.
2018-07-17 stefan@webrtc.org Reland "Move allocation and rtp conversion logic out of payload router."
2018-07-17 pitlicek@gmail.com Call callback in IDLE state


Created with:
  gclient setdep -r src/third_party/webrtc@dbdb3a00797d

The AutoRoll server is located here: https://webrtc-chromium-roll.skia.org

Documentation for the AutoRoller is here:
https://skia.googlesource.com/buildbot/+/master/autoroll/README.md

If the roll is causing failures, please contact the current sheriff, who should
be CC'd on the roll, and stop the roller if necessary.

CQ_INCLUDE_TRYBOTS=luci.chromium.try:linux_chromium_archive_rel_ng;master.tryserver.chromium.mac:mac_chromium_archive_rel_ng

BUG=chromium:None,chromium:None,chromium:690537,chromium:None,chromium:690537,chromium:840115,chromium:861557
TBR=webrtc-chromium-sheriffs-robots@google.com

Change-Id: I3b5867a0365875ae906aea0d9929dd6529c31160
Reviewed-on: https://chromium-review.googlesource.com/1140903
Reviewed-by: webrtc-chromium-autoroll <webrtc-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com>
Commit-Queue: webrtc-chromium-autoroll <webrtc-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com>
Cr-Commit-Position: refs/heads/master@{#575837}
[modify] https://crrev.com/c3323af925e5d404bc1371f22a45e61c5abeb7e7/DEPS

Project Member

Comment 12 by ClusterFuzz, Jul 18

ClusterFuzz has detected this issue as fixed in range 575824:575840.

Detailed report: https://clusterfuzz.com/testcase?key=5851238621773824

Fuzzer: libFuzzer_audio_decoder_isacfix_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Timeout (exceeds 25 secs)
Crash Address: 
Crash State:
  audio_decoder_isacfix_fuzzer
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=551565:551569
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=575824:575840

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5851238621773824

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 13 by ClusterFuzz, Jul 18

Labels: ClusterFuzz-Verified
Status: Verified (was: Started)
ClusterFuzz testcase 5851238621773824 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Labels: M-69

Sign in to add a comment