Assertion failure: mStart <= mEnd (Invalid Interval), at /builds/worker/workspace/obj-build/dist/include/Intervals.h:48
Categories
(Core :: Audio/Video, defect, P2)
Tracking
()
People
(Reporter: jkratzer, Assigned: padenot)
Details
(5 keywords, Whiteboard: [bugmon:bisected,confirmed][adv-main149+])
Attachments
(3 files)
Reproduced on mozilla-central rev 57fbf639ea5b (built with: --enable-debug --enable-fuzzing).
Testcase can be reproduced using the following commands:
$ pip install fuzzfetch grizzly-framework pipx --upgrade
$ python -m pipx ensurepath
$ fuzzfetch --build 57fbf639ea5b --debug --fuzzing -n firefox
$ grizzly-replay-bugzilla ./firefox/firefox <bugid>
Assertion failure: mStart <= mEnd (Invalid Interval), at /builds/worker/workspace/obj-build/dist/include/Intervals.h:48
==2879099==ERROR: UndefinedBehaviorSanitizer: SEGV on unknown address 0x000000000000 (pc 0x7df8ec852e82 bp 0x7ffd894e5930 sp 0x7ffd894e58a0 T2879099)
==2879099==The signal is caused by a WRITE memory access.
==2879099==Hint: address points to the zero page.
#0 0x7df8ec852e82 in MOZ_CrashSequence /builds/worker/workspace/obj-build/dist/include/mozilla/Assertions.h:237:3
#1 0x7df8ec852e82 in Interval<mozilla::media::TimeUnit &, mozilla::media::TimeUnit &> /builds/worker/workspace/obj-build/dist/include/Intervals.h:48:5
#2 0x7df8ec852e82 in mozilla::TrackBuffersManager::RangeRemoval(mozilla::media::TimeUnit, mozilla::media::TimeUnit) /dom/media/mediasource/TrackBuffersManager.cpp:330:22
#3 0x7df8ec852253 in mozilla::dom::SourceBuffer::RangeRemoval(double, double) /dom/media/mediasource/SourceBuffer.cpp:353:9
#4 0x7df8ec851edb in mozilla::dom::SourceBuffer::Remove(double, double, mozilla::ErrorResult&) /dom/media/mediasource/SourceBuffer.cpp:282:3
#5 0x7df8ead64392 in mozilla::dom::SourceBuffer_Binding::remove(JSContext*, JS::Handle<JSObject*>, void*, JSJitMethodCallArgs const&) /builds/worker/workspace/obj-build/dom/bindings/./SourceBufferBinding.cpp:1012:24
#6 0x7df8eb657df6 in bool mozilla::dom::binding_detail::GenericMethod<mozilla::dom::binding_detail::NormalThisPolicy, mozilla::dom::binding_detail::ThrowExceptions>(JSContext*, unsigned int, JS::Value*) /dom/bindings/BindingUtils.cpp:3309:13
#7 0x7df8f0223574 in CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&) /js/src/vm/Interpreter.cpp:490:13
#8 0x7df8f0222e1f in js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason) /js/src/vm/Interpreter.cpp:586:12
#9 0x7df8ef82cb83 in js::jit::DoCallFallback(JSContext*, js::jit::BaselineFrame*, js::jit::ICFallbackStub*, unsigned int, JS::Value*, JS::MutableHandle<JS::Value>) /js/src/jit/BaselineIC.cpp:1698:10
#10 0x2e520e81adee ([anon:js-executable-memory]+0xbdee)
==2879099==Register values:
rax = 0x0000000000000000 rbx = 0x00005fb755f27738 rcx = 0x0000000000000030 rdx = 0x00007df8f9a04563
rdi = 0x00007df8f9a05700 rsi = 0x0000000000000000 rbp = 0x00007ffd894e5930 rsp = 0x00007ffd894e58a0
r8 = 0x0000000000000000 r9 = 0x0000000000000003 r10 = 0x0000000000000002 r11 = 0x0000000000000293
r12 = 0x00007ffd894e5958 r13 = 0x00007ffd894e58c8 r14 = 0x00005fb755f26e60 r15 = 0x00005fb756075fc0
UndefinedBehaviorSanitizer can not provide additional info.
SUMMARY: UndefinedBehaviorSanitizer: SEGV (/home/jkratzer/builds/m-c-20260205090734-fuzzing-debug/libxul.so+0x9052e82) (BuildId: c143802c55c45c489dd220fc3aaf3f64e16a58ac)
==2879099==ABORTING
| Reporter | ||
Comment 1•7 months ago
|
||
| Reporter | ||
Comment 2•7 months ago
|
||
Updated•7 months ago
|
Comment 3•7 months ago
|
||
Verified bug as reproducible on mozilla-central 20260205213633-279b57ef4bf0.
Unable to bisect testcase (Testcase reproduces on start build!):
Start: ce0f77cae5a91e2cb4b1ec859117e08aa1182c52 (20250207164009)
End: 57fbf639ea5bd2e56dd9e1bef16497372385229d (20260205090734)
BuildFlags: BuildFlags(asan=False, tsan=False, debug=True, fuzzing=True, coverage=False, valgrind=False, no_opt=False, fuzzilli=False, nyx=False, searchfox=False, afl=False)
Updated•7 months ago
|
| Assignee | ||
Comment 4•7 months ago
|
||
TimeUnit::FromSeconds() had undefined behavior when converting values at the
boundary of int64_t representability. Specifically, when the input value times
the base equals exactly 2^63:
- static_cast<double>(INT64_MAX) rounds UP to 2^63 (INT64_MAX = 2^63-1 cannot
be exactly represented as double) - The check used strict >, so inBase == 2^63 passed the overflow check
- static_cast<int64_t>(std::round(2^63)) is undefined behavior since 2^63
exceeds INT64_MAX, producing INT64_MIN on x86-64 - This created invalid TimeUnits, causing assertion failures in TimeInterval
construction (mStart <= mEnd)
The fix changes > to >= to properly catch this boundary case.
Updated•7 months ago
|
Comment 5•7 months ago
|
||
I guess I'll mark it sec-moderate because of the undefined behavior, but it doesn't sound particularly exploitable.
Updated•7 months ago
|
Updated•7 months ago
|
Comment 7•7 months ago
|
||
Comment 8•7 months ago
|
||
Verified bug as fixed on rev mozilla-central 20260213044212-cabf73b570b5.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.
Updated•7 months ago
|
Updated•6 months ago
|
Updated•6 months ago
|
Updated•13 days ago
|
Description
•