Closed Bug 1458957 Opened 8 years ago Closed 7 years ago

Intermittent gtest AddressSanitizer: heap-use-after-free media/mtransport/sigslot.h:874:12 in disconnect_all

Categories

(Core :: WebRTC, defect, P2)

defect

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: RyanVM, Unassigned)

Details

(Keywords: csectype-uaf, intermittent-failure)

Looks a lot like bug 1436759, but that was fixed 3 months ago. https://queue.taskcluster.net/v1/task/NonEwXxCQsWvdNd26SVkfQ/runs/0/artifacts/public/logs/live_backing.log ERROR - ==968==ERROR: AddressSanitizer: heap-use-after-free on address 0x603001788460 at pc 0x7fa8e8214ed5 bp 0x7fa8df0a3f30 sp 0x7fa8df0a3f28 INFO - READ of size 8 at 0x603001788460 thread T4 (Socket Thread) INFO - #0 0x7fa8e8214ed4 in disconnect_all media/mtransport/sigslot.h:874:12 INFO - #1 0x7fa8e8214ed4 in sigslot::_signal_base2<mozilla::NrIceMediaStream*, std::string const&, sigslot::single_threaded>::~_signal_base2() media/mtransport/sigslot.h:855 INFO - #2 0x7fa8e82145e4 in mozilla::NrIceMediaStream::~NrIceMediaStream() media/mtransport/nricemediastream.cpp:224:1 INFO - #3 0x7fa8e829f61f in Release media/mtransport/nricemediastream.h:216:3 INFO - #4 0x7fa8e829f61f in Release obj-firefox/dist/include/mozilla/RefPtr.h:41 INFO - #5 0x7fa8e829f61f in Release obj-firefox/dist/include/mozilla/RefPtr.h:398 INFO - #6 0x7fa8e829f61f in ~RefPtr obj-firefox/dist/include/mozilla/RefPtr.h:79 INFO - #7 0x7fa8e829f61f in ~TransportLayerIce media/mtransport/transportlayerice.cpp:96 INFO - #8 0x7fa8e829f61f in mozilla::TransportLayerIce::~TransportLayerIce() media/mtransport/transportlayerice.cpp:94 INFO - #9 0x7fa8e824263c in ClearLayers media/mtransport/transportflow.cpp:59:5 INFO - #10 0x7fa8e824263c in mozilla::TransportFlow::DestroyFinal(nsAutoPtr<std::deque<mozilla::TransportLayer*, std::allocator<mozilla::TransportLayer*> > >) media/mtransport/transportflow.cpp:47 INFO - #11 0x7fa8e824aeec in apply<void (*)(nsAutoPtr<std::deque<mozilla::TransportLayer *, std::allocator<mozilla::TransportLayer *> > >), nsAutoPtr<std::deque<mozilla::TransportLayer *, std::allocator<mozilla::TransportLayer *> > > , 0> media/mtransport/runnable_utils.h:63:5 INFO - #12 0x7fa8e824aeec in mozilla::runnable_args_func<void (*)(nsAutoPtr<std::deque<mozilla::TransportLayer*, std::allocator<mozilla::TransportLayer*> > >), nsAutoPtr<std::deque<mozilla::TransportLayer*, std::allocator<mozilla::TransportLayer*> > > >::Run() media/mtransport/runnable_utils.h:103 INFO - #13 0x7fa8e65a7356 in nsThread::ProcessNextEvent(bool, bool*) xpcom/threads/nsThread.cpp:1090:14 INFO - #14 0x7fa8e65c04a0 in NS_ProcessNextEvent(nsIThread*, bool) xpcom/threads/nsThreadUtils.cpp:519:10 INFO - #15 0x7fa8e6808af4 in mozilla::net::nsSocketTransportService::Run() netwerk/base/nsSocketTransportService2.cpp:1007:21 INFO - #16 0x7fa8e680aeec in non-virtual thunk to mozilla::net::nsSocketTransportService::Run() netwerk/base/nsSocketTransportService2.cpp INFO - #17 0x7fa8e65a7356 in nsThread::ProcessNextEvent(bool, bool*) xpcom/threads/nsThread.cpp:1090:14 INFO - #18 0x7fa8e65c04a0 in NS_ProcessNextEvent(nsIThread*, bool) xpcom/threads/nsThreadUtils.cpp:519:10 INFO - #19 0x7fa8e7474deb in mozilla::ipc::MessagePumpForNonMainThreads::Run(base::MessagePump::Delegate*) ipc/glue/MessagePump.cpp:334:20 INFO - #20 0x7fa8e73cc049 in RunInternal ipc/chromium/src/base/message_loop.cc:326:10 INFO - #21 0x7fa8e73cc049 in RunHandler ipc/chromium/src/base/message_loop.cc:319 INFO - #22 0x7fa8e73cc049 in MessageLoop::Run() ipc/chromium/src/base/message_loop.cc:299 INFO - #23 0x7fa8e65a2759 in nsThread::ThreadFunc(void*) xpcom/threads/nsThread.cpp:425:11 INFO - #24 0x7fa904b4047e in _pt_root nsprpub/pr/src/pthreads/ptthread.c:201:5 INFO - #25 0x7fa90813a6b9 in start_thread (/lib/x86_64-linux-gnu/libpthread.so.0+0x76b9) INFO - #26 0x7fa9071c341c in clone /build/glibc-Cl5G7W/glibc-2.23/misc/../sysdeps/unix/sysv/linux/x86_64/clone.S:109 INFO - 0x603001788460 is located 0 bytes inside of 32-byte region [0x603001788460,0x603001788480) INFO - freed by thread T0 here: INFO - #0 0x4c1952 in __interceptor_free /builds/worker/workspace/moz-toolchain/src/llvm/projects/compiler-rt/lib/asan/asan_malloc_linux.cc:68:3 INFO - #1 0x7fa8e822401f in sigslot::_signal_base2<mozilla::NrIceMediaStream*, std::string const&, sigslot::single_threaded>::slot_disconnect(sigslot::has_slots_interface*) media/mtransport/sigslot.h:934:6 INFO - #2 0x7fa8f33647e4 in disconnect_all media/mtransport/sigslot.h:522:12 INFO - #3 0x7fa8f33647e4 in ~has_slots media/mtransport/sigslot.h:511 INFO - #4 0x7fa8f33647e4 in (anonymous namespace)::TransportTestPeer::~TransportTestPeer() media/mtransport/test/transport_unittests.cpp:475 INFO - #5 0x7fa8f3364b4d in (anonymous namespace)::TransportTestPeer::~TransportTestPeer() media/mtransport/test/transport_unittests.cpp:471:24 INFO - #6 0x7fa8f3361201 in (anonymous namespace)::TransportTest::TearDown() media/mtransport/test/transport_unittests.cpp:839:5 INFO - #7 0x7fa8f243fe94 in testing::TestInfo::Run() testing/gtest/gtest/src/gtest.cc:2658:11 INFO - #8 0x7fa8f2440ee6 in testing::TestCase::Run() testing/gtest/gtest/src/gtest.cc:2776:28 INFO - #9 0x7fa8f2457d76 in testing::internal::UnitTestImpl::RunAllTests() testing/gtest/gtest/src/gtest.cc:4651:43 INFO - #10 0x7fa8f245730a in testing::UnitTest::Run() testing/gtest/gtest/src/gtest.cc INFO - #11 0x7fa8f2488df8 in RUN_ALL_TESTS obj-firefox/dist/include/gtest/gtest.h:2233:46 INFO - #12 0x7fa8f2488df8 in mozilla::RunGTestFunc(int*, char**) testing/gtest/mozilla/GTestRunner.cpp:113 INFO - #13 0x7fa8f1268cf6 in XREMain::XRE_mainStartup(bool*) toolkit/xre/nsAppRunner.cpp:4035:16 INFO - #14 0x7fa8f127971b in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:4959:12 INFO - #15 0x7fa8f127aea4 in XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:5066:21 INFO - #16 0x4f168b in do_main browser/app/nsBrowserApp.cpp:231:22 INFO - #17 0x4f168b in main browser/app/nsBrowserApp.cpp:304 INFO - #18 0x7fa9070dc82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/csu/../csu/libc-start.c:291 INFO - previously allocated by thread T0 here: INFO - #0 0x4c1c93 in malloc /builds/worker/workspace/moz-toolchain/src/llvm/projects/compiler-rt/lib/asan/asan_malloc_linux.cc:88:3 INFO - #1 0x4f26fd in moz_xmalloc memory/mozalloc/mozalloc.cpp:70:17 INFO - #2 0x7fa8f3383846 in operator new obj-firefox/dist/include/mozilla/mozalloc.h:156:12 INFO - #3 0x7fa8f3383846 in connect<(anonymous namespace)::TransportTestPeer> media/mtransport/sigslot.h:2386 INFO - #4 0x7fa8f3383846 in (anonymous namespace)::TransportTestPeer::InitIce() media/mtransport/test/transport_unittests.cpp:615 INFO - #5 0x7fa8f3381c61 in (anonymous namespace)::TransportTest::ConnectIce() media/mtransport/test/transport_unittests.cpp:927:10 INFO - #6 0x7fa8f338a95e in (anonymous namespace)::TransportTest_TestTransferIceMaxSize_Test::TestBody() media/mtransport/test/transport_unittests.cpp:1208:3 INFO - #7 0x7fa8f243d97c in testing::Test::Run() testing/gtest/gtest/src/gtest-internal-inl.h INFO - #8 0x7fa8f243fe94 in testing::TestInfo::Run() testing/gtest/gtest/src/gtest.cc:2658:11 INFO - #9 0x7fa8f2440ee6 in testing::TestCase::Run() testing/gtest/gtest/src/gtest.cc:2776:28 INFO - #10 0x7fa8f2457d76 in testing::internal::UnitTestImpl::RunAllTests() testing/gtest/gtest/src/gtest.cc:4651:43 INFO - #11 0x7fa8f245730a in testing::UnitTest::Run() testing/gtest/gtest/src/gtest.cc INFO - #12 0x7fa8f2488df8 in RUN_ALL_TESTS obj-firefox/dist/include/gtest/gtest.h:2233:46 INFO - #13 0x7fa8f2488df8 in mozilla::RunGTestFunc(int*, char**) testing/gtest/mozilla/GTestRunner.cpp:113 INFO - #14 0x7fa8f1268cf6 in XREMain::XRE_mainStartup(bool*) toolkit/xre/nsAppRunner.cpp:4035:16 INFO - #15 0x7fa8f127971b in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:4959:12 INFO - #16 0x7fa8f127aea4 in XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:5066:21 INFO - #17 0x4f168b in do_main browser/app/nsBrowserApp.cpp:231:22 INFO - #18 0x4f168b in main browser/app/nsBrowserApp.cpp:304 INFO - #19 0x7fa9070dc82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/csu/../csu/libc-start.c:291 INFO - Thread T4 (Socket Thread) created by T0 here: INFO - #0 0x4aafed in __interceptor_pthread_create /builds/worker/workspace/moz-toolchain/src/llvm/projects/compiler-rt/lib/asan/asan_interceptors.cc:204:3 INFO - #1 0x7fa904b3d1cf in _PR_CreateThread nsprpub/pr/src/pthreads/ptthread.c:433:14 INFO - #2 0x7fa904b3cdbe in PR_CreateThread nsprpub/pr/src/pthreads/ptthread.c:518:12 INFO - #3 0x7fa8e65a4578 in nsThread::Init(nsTSubstring<char> const&) xpcom/threads/nsThread.cpp:608:8 INFO - #4 0x7fa8e65ac63a in nsThreadManager::NewNamedThread(nsTSubstring<char> const&, unsigned int, nsIThread**) xpcom/threads/nsThreadManager.cpp:471:22 INFO - #5 0x7fa8e65bad74 in NS_NewNamedThread(nsTSubstring<char> const&, nsIThread**, nsIRunnable*, unsigned int) xpcom/threads/nsThreadUtils.cpp:143:45 INFO - #6 0x7fa8e6805968 in NS_NewNamedThread<14> obj-firefox/dist/include/nsThreadUtils.h:73:10 INFO - #7 0x7fa8e6805968 in mozilla::net::nsSocketTransportService::Init() netwerk/base/nsSocketTransportService2.cpp:590 INFO - #8 0x7fa8e73a746c in nsSocketTransportServiceConstructor(nsISupports*, nsID const&, void**) netwerk/build/nsNetModule.cpp:75:1 INFO - #9 0x7fa8e655e5c5 in nsComponentManagerImpl::CreateInstanceByContractID(char const*, nsISupports*, nsID const&, void**) xpcom/components/nsComponentManager.cpp:1049:19 INFO - #10 0x7fa8e6555c3d in nsComponentManagerImpl::GetServiceByContractID(char const*, nsID const&, void**) xpcom/components/nsComponentManager.cpp:1409:10 INFO - #11 0x7fa8e65645d5 in CallGetService xpcom/components/nsComponentManagerUtils.cpp:67:43 INFO - #12 0x7fa8e65645d5 in nsGetServiceByContractIDWithError::operator()(nsID const&, void**) const xpcom/components/nsComponentManagerUtils.cpp:292 INFO - #13 0x7fa8e6424dea in nsCOMPtr_base::assign_from_gs_contractid_with_error(nsGetServiceByContractIDWithError const&, nsID const&) xpcom/base/nsCOMPtr.cpp:106:7 INFO - #14 0x7fa8e6760f40 in operator= obj-firefox/dist/include/nsCOMPtr.h:704:5 INFO - #15 0x7fa8e6760f40 in InitializeSocketTransportService netwerk/base/nsIOService.cpp:296 INFO - #16 0x7fa8e6760f40 in mozilla::net::nsIOService::SetOffline(bool) netwerk/base/nsIOService.cpp:1145 INFO - #17 0x7fa8e6760046 in mozilla::net::nsIOService::Init() netwerk/base/nsIOService.cpp:260:5 INFO - #18 0x7fa8e67628ed in mozilla::net::nsIOService::GetInstance() netwerk/base/nsIOService.cpp:357:13 INFO - #19 0x7fa8e73a7257 in nsIOServiceConstructor(nsISupports*, nsID const&, void**) netwerk/build/nsNetModule.cpp:57:1 INFO - #20 0x7fa8e655e5c5 in nsComponentManagerImpl::CreateInstanceByContractID(char const*, nsISupports*, nsID const&, void**) xpcom/components/nsComponentManager.cpp:1049:19 INFO - #21 0x7fa8e6555c3d in nsComponentManagerImpl::GetServiceByContractID(char const*, nsID const&, void**) xpcom/components/nsComponentManager.cpp:1409:10 INFO - #22 0x7fa8e656453c in CallGetService xpcom/components/nsComponentManagerUtils.cpp:67:43 INFO - #23 0x7fa8e656453c in nsGetServiceByContractID::operator()(nsID const&, void**) const xpcom/components/nsComponentManagerUtils.cpp:280 INFO - #24 0x7fa8e6424c09 in nsCOMPtr_base::assign_from_gs_contractid(nsGetServiceByContractID, nsID const&) xpcom/base/nsCOMPtr.cpp:95:7 INFO - #25 0x7fa8e65efdea in nsCOMPtr obj-firefox/dist/include/nsCOMPtr.h:577:5 INFO - #26 0x7fa8e65efdea in XPCOMService_GetIOService obj-firefox/xpcom/build/Services.cpp:132 INFO - #27 0x7fa8e67a38be in GetIOService obj-firefox/dist/include/mozilla/Services.h:128:41 INFO - #28 0x7fa8e67a38be in do_GetIOService netwerk/base/nsNetUtil.cpp:100 INFO - #29 0x7fa8e67a38be in net_EnsureIOService netwerk/base/nsNetUtil.cpp:147 INFO - #30 0x7fa8e67a38be in NS_NewURI(nsIURI**, nsTSubstring<char> const&, char const*, nsIURI*, nsIIOService*) netwerk/base/nsNetUtil.cpp:1920 INFO - #31 0x7fa8e65e4fb2 in GetManifestURI chrome/nsChromeRegistryChrome.cpp:616:5 INFO - #32 0x7fa8e65e4fb2 in nsChromeRegistry::ManifestProcessingContext::ResolveURI(char const*) chrome/nsChromeRegistryChrome.cpp:624 INFO - #33 0x7fa8e65e536a in nsChromeRegistryChrome::ManifestContent(nsChromeRegistry::ManifestProcessingContext&, int, char* const*, int) chrome/nsChromeRegistryChrome.cpp:668:34 INFO - #34 0x7fa8e654a285 in ParseManifest(NSLocationType, mozilla::FileLocation&, char*, bool) xpcom/components/ManifestParser.cpp:729:7 INFO - #35 0x7fa8e655a249 in DoRegisterManifest xpcom/components/nsComponentManager.cpp:541:5 INFO - #36 0x7fa8e655a249 in nsComponentManagerImpl::RegisterManifest(NSLocationType, mozilla::FileLocation&, bool) xpcom/components/nsComponentManager.cpp:554 INFO - #37 0x7fa8e655a507 in nsComponentManagerImpl::ManifestManifest(nsComponentManagerImpl::ManifestProcessingContext&, int, char* const*) xpcom/components/nsComponentManager.cpp:563:3 INFO - #38 0x7fa8e654a57c in ParseManifest(NSLocationType, mozilla::FileLocation&, char*, bool) xpcom/components/ManifestParser.cpp:738:9 INFO - #39 0x7fa8e655a249 in DoRegisterManifest xpcom/components/nsComponentManager.cpp:541:5 INFO - #40 0x7fa8e655a249 in nsComponentManagerImpl::RegisterManifest(NSLocationType, mozilla::FileLocation&, bool) xpcom/components/nsComponentManager.cpp:554 INFO - #41 0x7fa8e6558d76 in nsComponentManagerImpl::RereadChromeManifests(bool) xpcom/components/nsComponentManager.cpp:684:5 INFO - #42 0x7fa8e6557675 in nsComponentManagerImpl::Init() xpcom/components/nsComponentManager.cpp:349:5 INFO - #43 0x7fa8e65fe1c3 in NS_InitXPCOM2 xpcom/build/XPCOMInit.cpp:649:51 INFO - #44 0x7fa8f2488a06 in ScopedXPCOM obj-firefox/dist/include/testing/TestHarness.h:89:21 INFO - #45 0x7fa8f2488a06 in mozilla::RunGTestFunc(int*, char**) testing/gtest/mozilla/GTestRunner.cpp:87 INFO - #46 0x7fa8f1268cf6 in XREMain::XRE_mainStartup(bool*) toolkit/xre/nsAppRunner.cpp:4035:16 INFO - #47 0x7fa8f127971b in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:4959:12 INFO - #48 0x7fa8f127aea4 in XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:5066:21 INFO - #49 0x4f168b in do_main browser/app/nsBrowserApp.cpp:231:22 INFO - #50 0x4f168b in main browser/app/nsBrowserApp.cpp:304 INFO - #51 0x7fa9070dc82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/csu/../csu/libc-start.c:291 INFO - SUMMARY: AddressSanitizer: heap-use-after-free media/mtransport/sigslot.h:874:12 in disconnect_all INFO - Shadow bytes around the buggy address: INFO - 0x0c06802e9030: fa fa 00 00 00 fa fa fa fd fd fd fa fa fa fd fd INFO - 0x0c06802e9040: fd fd fa fa 00 00 00 00 fa fa fd fd fd fd fa fa INFO - 0x0c06802e9050: fa fa fa fa fa fa 00 00 00 05 fa fa 00 00 00 fa INFO - 0x0c06802e9060: fa fa fd fd fd fa fa fa fd fd fd fd fa fa 00 00 INFO - 0x0c06802e9070: 00 fa fa fa fd fd fd fa fa fa fd fd fd fa fa fa INFO - =>0x0c06802e9080: 00 00 00 00 fa fa fd fd fd fd fa fa[fd]fd fd fd INFO - 0x0c06802e9090: fa fa fd fd fd fd fa fa 00 00 00 00 fa fa fd fd INFO - 0x0c06802e90a0: fd fa fa fa fd fd fd fd fa fa fd fd fd fd fa fa INFO - 0x0c06802e90b0: fd fd fd fd fa fa fa fa fa fa fa fa fd fd fd fd INFO - 0x0c06802e90c0: fa fa fd fd fd fd fa fa fa fa fa fa fa fa fd fd INFO - 0x0c06802e90d0: fd fd fa fa fd fd fd fd fa fa fd fd fd fa fa fa INFO - Shadow byte legend (one shadow byte represents 8 application bytes): INFO - Addressable: 00 INFO - Partially addressable: 01 02 03 04 05 06 07 INFO - Heap left redzone: fa INFO - Freed heap region: fd INFO - Stack left redzone: f1 INFO - Stack mid redzone: f2 INFO - Stack right redzone: f3 INFO - Stack after return: f5 INFO - Stack use after scope: f8 INFO - Global redzone: f9 INFO - Global init order: f6 INFO - Poisoned by user: f7 INFO - Container overflow: fc INFO - Array cookie: ac INFO - Intra object redzone: bb INFO - ASan internal: fe INFO - Left alloca redzone: ca INFO - Right alloca redzone: cb INFO - ==968==ABORTING ERROR - gtest TEST-UNEXPECTED-FAIL | gtest | test failed with return code 1
To me, this looks like a bug in the test-case, not a sec bug.
Yep - the other was a test bug as well.
Group: media-core-security

I'm not seeing anything in the treeherder link above. Did these get re-classified or something?

Flags: needinfo?(ryanvm)

Records eventually get purged. This was filed over a year ago and the log is long-gone. Given that there haven't been any reports since, we can probably just call it WFM.

Status: NEW → RESOLVED
Closed: 7 years ago
Flags: needinfo?(ryanvm)
Resolution: --- → WORKSFORME

I'm talking about comment 3 from 5 days ago.

Flags: needinfo?(ryanvm)

Yeah, must have been reclassified. OrangeFactor uses the live Treeherder DB nowadays instead of its own copy of classification data.

Flags: needinfo?(ryanvm)
You need to log in before you can comment on or make changes to this bug.