Closed
Bug 1458957
Opened 8 years ago
Closed 7 years ago
Intermittent gtest AddressSanitizer: heap-use-after-free media/mtransport/sigslot.h:874:12 in disconnect_all
Categories
(Core :: WebRTC, defect, P2)
Core
WebRTC
Tracking
()
RESOLVED
WORKSFORME
People
(Reporter: RyanVM, Unassigned)
Details
(Keywords: csectype-uaf, intermittent-failure)
Looks a lot like bug 1436759, but that was fixed 3 months ago.
https://queue.taskcluster.net/v1/task/NonEwXxCQsWvdNd26SVkfQ/runs/0/artifacts/public/logs/live_backing.log
ERROR - ==968==ERROR: AddressSanitizer: heap-use-after-free on address 0x603001788460 at pc 0x7fa8e8214ed5 bp 0x7fa8df0a3f30 sp 0x7fa8df0a3f28
INFO - READ of size 8 at 0x603001788460 thread T4 (Socket Thread)
INFO - #0 0x7fa8e8214ed4 in disconnect_all media/mtransport/sigslot.h:874:12
INFO - #1 0x7fa8e8214ed4 in sigslot::_signal_base2<mozilla::NrIceMediaStream*, std::string const&, sigslot::single_threaded>::~_signal_base2() media/mtransport/sigslot.h:855
INFO - #2 0x7fa8e82145e4 in mozilla::NrIceMediaStream::~NrIceMediaStream() media/mtransport/nricemediastream.cpp:224:1
INFO - #3 0x7fa8e829f61f in Release media/mtransport/nricemediastream.h:216:3
INFO - #4 0x7fa8e829f61f in Release obj-firefox/dist/include/mozilla/RefPtr.h:41
INFO - #5 0x7fa8e829f61f in Release obj-firefox/dist/include/mozilla/RefPtr.h:398
INFO - #6 0x7fa8e829f61f in ~RefPtr obj-firefox/dist/include/mozilla/RefPtr.h:79
INFO - #7 0x7fa8e829f61f in ~TransportLayerIce media/mtransport/transportlayerice.cpp:96
INFO - #8 0x7fa8e829f61f in mozilla::TransportLayerIce::~TransportLayerIce() media/mtransport/transportlayerice.cpp:94
INFO - #9 0x7fa8e824263c in ClearLayers media/mtransport/transportflow.cpp:59:5
INFO - #10 0x7fa8e824263c in mozilla::TransportFlow::DestroyFinal(nsAutoPtr<std::deque<mozilla::TransportLayer*, std::allocator<mozilla::TransportLayer*> > >) media/mtransport/transportflow.cpp:47
INFO - #11 0x7fa8e824aeec in apply<void (*)(nsAutoPtr<std::deque<mozilla::TransportLayer *, std::allocator<mozilla::TransportLayer *> > >), nsAutoPtr<std::deque<mozilla::TransportLayer *, std::allocator<mozilla::TransportLayer *> > > , 0> media/mtransport/runnable_utils.h:63:5
INFO - #12 0x7fa8e824aeec in mozilla::runnable_args_func<void (*)(nsAutoPtr<std::deque<mozilla::TransportLayer*, std::allocator<mozilla::TransportLayer*> > >), nsAutoPtr<std::deque<mozilla::TransportLayer*, std::allocator<mozilla::TransportLayer*> > > >::Run() media/mtransport/runnable_utils.h:103
INFO - #13 0x7fa8e65a7356 in nsThread::ProcessNextEvent(bool, bool*) xpcom/threads/nsThread.cpp:1090:14
INFO - #14 0x7fa8e65c04a0 in NS_ProcessNextEvent(nsIThread*, bool) xpcom/threads/nsThreadUtils.cpp:519:10
INFO - #15 0x7fa8e6808af4 in mozilla::net::nsSocketTransportService::Run() netwerk/base/nsSocketTransportService2.cpp:1007:21
INFO - #16 0x7fa8e680aeec in non-virtual thunk to mozilla::net::nsSocketTransportService::Run() netwerk/base/nsSocketTransportService2.cpp
INFO - #17 0x7fa8e65a7356 in nsThread::ProcessNextEvent(bool, bool*) xpcom/threads/nsThread.cpp:1090:14
INFO - #18 0x7fa8e65c04a0 in NS_ProcessNextEvent(nsIThread*, bool) xpcom/threads/nsThreadUtils.cpp:519:10
INFO - #19 0x7fa8e7474deb in mozilla::ipc::MessagePumpForNonMainThreads::Run(base::MessagePump::Delegate*) ipc/glue/MessagePump.cpp:334:20
INFO - #20 0x7fa8e73cc049 in RunInternal ipc/chromium/src/base/message_loop.cc:326:10
INFO - #21 0x7fa8e73cc049 in RunHandler ipc/chromium/src/base/message_loop.cc:319
INFO - #22 0x7fa8e73cc049 in MessageLoop::Run() ipc/chromium/src/base/message_loop.cc:299
INFO - #23 0x7fa8e65a2759 in nsThread::ThreadFunc(void*) xpcom/threads/nsThread.cpp:425:11
INFO - #24 0x7fa904b4047e in _pt_root nsprpub/pr/src/pthreads/ptthread.c:201:5
INFO - #25 0x7fa90813a6b9 in start_thread (/lib/x86_64-linux-gnu/libpthread.so.0+0x76b9)
INFO - #26 0x7fa9071c341c in clone /build/glibc-Cl5G7W/glibc-2.23/misc/../sysdeps/unix/sysv/linux/x86_64/clone.S:109
INFO - 0x603001788460 is located 0 bytes inside of 32-byte region [0x603001788460,0x603001788480)
INFO - freed by thread T0 here:
INFO - #0 0x4c1952 in __interceptor_free /builds/worker/workspace/moz-toolchain/src/llvm/projects/compiler-rt/lib/asan/asan_malloc_linux.cc:68:3
INFO - #1 0x7fa8e822401f in sigslot::_signal_base2<mozilla::NrIceMediaStream*, std::string const&, sigslot::single_threaded>::slot_disconnect(sigslot::has_slots_interface*) media/mtransport/sigslot.h:934:6
INFO - #2 0x7fa8f33647e4 in disconnect_all media/mtransport/sigslot.h:522:12
INFO - #3 0x7fa8f33647e4 in ~has_slots media/mtransport/sigslot.h:511
INFO - #4 0x7fa8f33647e4 in (anonymous namespace)::TransportTestPeer::~TransportTestPeer() media/mtransport/test/transport_unittests.cpp:475
INFO - #5 0x7fa8f3364b4d in (anonymous namespace)::TransportTestPeer::~TransportTestPeer() media/mtransport/test/transport_unittests.cpp:471:24
INFO - #6 0x7fa8f3361201 in (anonymous namespace)::TransportTest::TearDown() media/mtransport/test/transport_unittests.cpp:839:5
INFO - #7 0x7fa8f243fe94 in testing::TestInfo::Run() testing/gtest/gtest/src/gtest.cc:2658:11
INFO - #8 0x7fa8f2440ee6 in testing::TestCase::Run() testing/gtest/gtest/src/gtest.cc:2776:28
INFO - #9 0x7fa8f2457d76 in testing::internal::UnitTestImpl::RunAllTests() testing/gtest/gtest/src/gtest.cc:4651:43
INFO - #10 0x7fa8f245730a in testing::UnitTest::Run() testing/gtest/gtest/src/gtest.cc
INFO - #11 0x7fa8f2488df8 in RUN_ALL_TESTS obj-firefox/dist/include/gtest/gtest.h:2233:46
INFO - #12 0x7fa8f2488df8 in mozilla::RunGTestFunc(int*, char**) testing/gtest/mozilla/GTestRunner.cpp:113
INFO - #13 0x7fa8f1268cf6 in XREMain::XRE_mainStartup(bool*) toolkit/xre/nsAppRunner.cpp:4035:16
INFO - #14 0x7fa8f127971b in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:4959:12
INFO - #15 0x7fa8f127aea4 in XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:5066:21
INFO - #16 0x4f168b in do_main browser/app/nsBrowserApp.cpp:231:22
INFO - #17 0x4f168b in main browser/app/nsBrowserApp.cpp:304
INFO - #18 0x7fa9070dc82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/csu/../csu/libc-start.c:291
INFO - previously allocated by thread T0 here:
INFO - #0 0x4c1c93 in malloc /builds/worker/workspace/moz-toolchain/src/llvm/projects/compiler-rt/lib/asan/asan_malloc_linux.cc:88:3
INFO - #1 0x4f26fd in moz_xmalloc memory/mozalloc/mozalloc.cpp:70:17
INFO - #2 0x7fa8f3383846 in operator new obj-firefox/dist/include/mozilla/mozalloc.h:156:12
INFO - #3 0x7fa8f3383846 in connect<(anonymous namespace)::TransportTestPeer> media/mtransport/sigslot.h:2386
INFO - #4 0x7fa8f3383846 in (anonymous namespace)::TransportTestPeer::InitIce() media/mtransport/test/transport_unittests.cpp:615
INFO - #5 0x7fa8f3381c61 in (anonymous namespace)::TransportTest::ConnectIce() media/mtransport/test/transport_unittests.cpp:927:10
INFO - #6 0x7fa8f338a95e in (anonymous namespace)::TransportTest_TestTransferIceMaxSize_Test::TestBody() media/mtransport/test/transport_unittests.cpp:1208:3
INFO - #7 0x7fa8f243d97c in testing::Test::Run() testing/gtest/gtest/src/gtest-internal-inl.h
INFO - #8 0x7fa8f243fe94 in testing::TestInfo::Run() testing/gtest/gtest/src/gtest.cc:2658:11
INFO - #9 0x7fa8f2440ee6 in testing::TestCase::Run() testing/gtest/gtest/src/gtest.cc:2776:28
INFO - #10 0x7fa8f2457d76 in testing::internal::UnitTestImpl::RunAllTests() testing/gtest/gtest/src/gtest.cc:4651:43
INFO - #11 0x7fa8f245730a in testing::UnitTest::Run() testing/gtest/gtest/src/gtest.cc
INFO - #12 0x7fa8f2488df8 in RUN_ALL_TESTS obj-firefox/dist/include/gtest/gtest.h:2233:46
INFO - #13 0x7fa8f2488df8 in mozilla::RunGTestFunc(int*, char**) testing/gtest/mozilla/GTestRunner.cpp:113
INFO - #14 0x7fa8f1268cf6 in XREMain::XRE_mainStartup(bool*) toolkit/xre/nsAppRunner.cpp:4035:16
INFO - #15 0x7fa8f127971b in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:4959:12
INFO - #16 0x7fa8f127aea4 in XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:5066:21
INFO - #17 0x4f168b in do_main browser/app/nsBrowserApp.cpp:231:22
INFO - #18 0x4f168b in main browser/app/nsBrowserApp.cpp:304
INFO - #19 0x7fa9070dc82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/csu/../csu/libc-start.c:291
INFO - Thread T4 (Socket Thread) created by T0 here:
INFO - #0 0x4aafed in __interceptor_pthread_create /builds/worker/workspace/moz-toolchain/src/llvm/projects/compiler-rt/lib/asan/asan_interceptors.cc:204:3
INFO - #1 0x7fa904b3d1cf in _PR_CreateThread nsprpub/pr/src/pthreads/ptthread.c:433:14
INFO - #2 0x7fa904b3cdbe in PR_CreateThread nsprpub/pr/src/pthreads/ptthread.c:518:12
INFO - #3 0x7fa8e65a4578 in nsThread::Init(nsTSubstring<char> const&) xpcom/threads/nsThread.cpp:608:8
INFO - #4 0x7fa8e65ac63a in nsThreadManager::NewNamedThread(nsTSubstring<char> const&, unsigned int, nsIThread**) xpcom/threads/nsThreadManager.cpp:471:22
INFO - #5 0x7fa8e65bad74 in NS_NewNamedThread(nsTSubstring<char> const&, nsIThread**, nsIRunnable*, unsigned int) xpcom/threads/nsThreadUtils.cpp:143:45
INFO - #6 0x7fa8e6805968 in NS_NewNamedThread<14> obj-firefox/dist/include/nsThreadUtils.h:73:10
INFO - #7 0x7fa8e6805968 in mozilla::net::nsSocketTransportService::Init() netwerk/base/nsSocketTransportService2.cpp:590
INFO - #8 0x7fa8e73a746c in nsSocketTransportServiceConstructor(nsISupports*, nsID const&, void**) netwerk/build/nsNetModule.cpp:75:1
INFO - #9 0x7fa8e655e5c5 in nsComponentManagerImpl::CreateInstanceByContractID(char const*, nsISupports*, nsID const&, void**) xpcom/components/nsComponentManager.cpp:1049:19
INFO - #10 0x7fa8e6555c3d in nsComponentManagerImpl::GetServiceByContractID(char const*, nsID const&, void**) xpcom/components/nsComponentManager.cpp:1409:10
INFO - #11 0x7fa8e65645d5 in CallGetService xpcom/components/nsComponentManagerUtils.cpp:67:43
INFO - #12 0x7fa8e65645d5 in nsGetServiceByContractIDWithError::operator()(nsID const&, void**) const xpcom/components/nsComponentManagerUtils.cpp:292
INFO - #13 0x7fa8e6424dea in nsCOMPtr_base::assign_from_gs_contractid_with_error(nsGetServiceByContractIDWithError const&, nsID const&) xpcom/base/nsCOMPtr.cpp:106:7
INFO - #14 0x7fa8e6760f40 in operator= obj-firefox/dist/include/nsCOMPtr.h:704:5
INFO - #15 0x7fa8e6760f40 in InitializeSocketTransportService netwerk/base/nsIOService.cpp:296
INFO - #16 0x7fa8e6760f40 in mozilla::net::nsIOService::SetOffline(bool) netwerk/base/nsIOService.cpp:1145
INFO - #17 0x7fa8e6760046 in mozilla::net::nsIOService::Init() netwerk/base/nsIOService.cpp:260:5
INFO - #18 0x7fa8e67628ed in mozilla::net::nsIOService::GetInstance() netwerk/base/nsIOService.cpp:357:13
INFO - #19 0x7fa8e73a7257 in nsIOServiceConstructor(nsISupports*, nsID const&, void**) netwerk/build/nsNetModule.cpp:57:1
INFO - #20 0x7fa8e655e5c5 in nsComponentManagerImpl::CreateInstanceByContractID(char const*, nsISupports*, nsID const&, void**) xpcom/components/nsComponentManager.cpp:1049:19
INFO - #21 0x7fa8e6555c3d in nsComponentManagerImpl::GetServiceByContractID(char const*, nsID const&, void**) xpcom/components/nsComponentManager.cpp:1409:10
INFO - #22 0x7fa8e656453c in CallGetService xpcom/components/nsComponentManagerUtils.cpp:67:43
INFO - #23 0x7fa8e656453c in nsGetServiceByContractID::operator()(nsID const&, void**) const xpcom/components/nsComponentManagerUtils.cpp:280
INFO - #24 0x7fa8e6424c09 in nsCOMPtr_base::assign_from_gs_contractid(nsGetServiceByContractID, nsID const&) xpcom/base/nsCOMPtr.cpp:95:7
INFO - #25 0x7fa8e65efdea in nsCOMPtr obj-firefox/dist/include/nsCOMPtr.h:577:5
INFO - #26 0x7fa8e65efdea in XPCOMService_GetIOService obj-firefox/xpcom/build/Services.cpp:132
INFO - #27 0x7fa8e67a38be in GetIOService obj-firefox/dist/include/mozilla/Services.h:128:41
INFO - #28 0x7fa8e67a38be in do_GetIOService netwerk/base/nsNetUtil.cpp:100
INFO - #29 0x7fa8e67a38be in net_EnsureIOService netwerk/base/nsNetUtil.cpp:147
INFO - #30 0x7fa8e67a38be in NS_NewURI(nsIURI**, nsTSubstring<char> const&, char const*, nsIURI*, nsIIOService*) netwerk/base/nsNetUtil.cpp:1920
INFO - #31 0x7fa8e65e4fb2 in GetManifestURI chrome/nsChromeRegistryChrome.cpp:616:5
INFO - #32 0x7fa8e65e4fb2 in nsChromeRegistry::ManifestProcessingContext::ResolveURI(char const*) chrome/nsChromeRegistryChrome.cpp:624
INFO - #33 0x7fa8e65e536a in nsChromeRegistryChrome::ManifestContent(nsChromeRegistry::ManifestProcessingContext&, int, char* const*, int) chrome/nsChromeRegistryChrome.cpp:668:34
INFO - #34 0x7fa8e654a285 in ParseManifest(NSLocationType, mozilla::FileLocation&, char*, bool) xpcom/components/ManifestParser.cpp:729:7
INFO - #35 0x7fa8e655a249 in DoRegisterManifest xpcom/components/nsComponentManager.cpp:541:5
INFO - #36 0x7fa8e655a249 in nsComponentManagerImpl::RegisterManifest(NSLocationType, mozilla::FileLocation&, bool) xpcom/components/nsComponentManager.cpp:554
INFO - #37 0x7fa8e655a507 in nsComponentManagerImpl::ManifestManifest(nsComponentManagerImpl::ManifestProcessingContext&, int, char* const*) xpcom/components/nsComponentManager.cpp:563:3
INFO - #38 0x7fa8e654a57c in ParseManifest(NSLocationType, mozilla::FileLocation&, char*, bool) xpcom/components/ManifestParser.cpp:738:9
INFO - #39 0x7fa8e655a249 in DoRegisterManifest xpcom/components/nsComponentManager.cpp:541:5
INFO - #40 0x7fa8e655a249 in nsComponentManagerImpl::RegisterManifest(NSLocationType, mozilla::FileLocation&, bool) xpcom/components/nsComponentManager.cpp:554
INFO - #41 0x7fa8e6558d76 in nsComponentManagerImpl::RereadChromeManifests(bool) xpcom/components/nsComponentManager.cpp:684:5
INFO - #42 0x7fa8e6557675 in nsComponentManagerImpl::Init() xpcom/components/nsComponentManager.cpp:349:5
INFO - #43 0x7fa8e65fe1c3 in NS_InitXPCOM2 xpcom/build/XPCOMInit.cpp:649:51
INFO - #44 0x7fa8f2488a06 in ScopedXPCOM obj-firefox/dist/include/testing/TestHarness.h:89:21
INFO - #45 0x7fa8f2488a06 in mozilla::RunGTestFunc(int*, char**) testing/gtest/mozilla/GTestRunner.cpp:87
INFO - #46 0x7fa8f1268cf6 in XREMain::XRE_mainStartup(bool*) toolkit/xre/nsAppRunner.cpp:4035:16
INFO - #47 0x7fa8f127971b in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:4959:12
INFO - #48 0x7fa8f127aea4 in XRE_main(int, char**, mozilla::BootstrapConfig const&) toolkit/xre/nsAppRunner.cpp:5066:21
INFO - #49 0x4f168b in do_main browser/app/nsBrowserApp.cpp:231:22
INFO - #50 0x4f168b in main browser/app/nsBrowserApp.cpp:304
INFO - #51 0x7fa9070dc82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/csu/../csu/libc-start.c:291
INFO - SUMMARY: AddressSanitizer: heap-use-after-free media/mtransport/sigslot.h:874:12 in disconnect_all
INFO - Shadow bytes around the buggy address:
INFO - 0x0c06802e9030: fa fa 00 00 00 fa fa fa fd fd fd fa fa fa fd fd
INFO - 0x0c06802e9040: fd fd fa fa 00 00 00 00 fa fa fd fd fd fd fa fa
INFO - 0x0c06802e9050: fa fa fa fa fa fa 00 00 00 05 fa fa 00 00 00 fa
INFO - 0x0c06802e9060: fa fa fd fd fd fa fa fa fd fd fd fd fa fa 00 00
INFO - 0x0c06802e9070: 00 fa fa fa fd fd fd fa fa fa fd fd fd fa fa fa
INFO - =>0x0c06802e9080: 00 00 00 00 fa fa fd fd fd fd fa fa[fd]fd fd fd
INFO - 0x0c06802e9090: fa fa fd fd fd fd fa fa 00 00 00 00 fa fa fd fd
INFO - 0x0c06802e90a0: fd fa fa fa fd fd fd fd fa fa fd fd fd fd fa fa
INFO - 0x0c06802e90b0: fd fd fd fd fa fa fa fa fa fa fa fa fd fd fd fd
INFO - 0x0c06802e90c0: fa fa fd fd fd fd fa fa fa fa fa fa fa fa fd fd
INFO - 0x0c06802e90d0: fd fd fa fa fd fd fd fd fa fa fd fd fd fa fa fa
INFO - Shadow byte legend (one shadow byte represents 8 application bytes):
INFO - Addressable: 00
INFO - Partially addressable: 01 02 03 04 05 06 07
INFO - Heap left redzone: fa
INFO - Freed heap region: fd
INFO - Stack left redzone: f1
INFO - Stack mid redzone: f2
INFO - Stack right redzone: f3
INFO - Stack after return: f5
INFO - Stack use after scope: f8
INFO - Global redzone: f9
INFO - Global init order: f6
INFO - Poisoned by user: f7
INFO - Container overflow: fc
INFO - Array cookie: ac
INFO - Intra object redzone: bb
INFO - ASan internal: fe
INFO - Left alloca redzone: ca
INFO - Right alloca redzone: cb
INFO - ==968==ABORTING
ERROR - gtest TEST-UNEXPECTED-FAIL | gtest | test failed with return code 1
Comment 1•8 years ago
|
||
To me, this looks like a bug in the test-case, not a sec bug.
Comment 2•8 years ago
|
||
Yep - the other was a test bug as well.
Updated•8 years ago
|
Group: media-core-security
| Comment hidden (Intermittent Failures Robot) |
Comment 4•7 years ago
|
||
I'm not seeing anything in the treeherder link above. Did these get re-classified or something?
Flags: needinfo?(ryanvm)
| Reporter | ||
Comment 5•7 years ago
|
||
Records eventually get purged. This was filed over a year ago and the log is long-gone. Given that there haven't been any reports since, we can probably just call it WFM.
Status: NEW → RESOLVED
Closed: 7 years ago
Flags: needinfo?(ryanvm)
Resolution: --- → WORKSFORME
| Reporter | ||
Comment 7•7 years ago
|
||
Yeah, must have been reclassified. OrangeFactor uses the live Treeherder DB nowadays instead of its own copy of classification data.
Flags: needinfo?(ryanvm)
You need to log in
before you can comment on or make changes to this bug.
Description
•