New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 605896 link

Starred by 0 users

Issue metadata

Status: Duplicate
Merged: issue 605479
Owner:
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Data race in SkROBuffer::Iter::next

Project Member Reported by ClusterFuzz, Apr 22 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5434198067773440

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race READ 8
Crash Address: 0x7d84000ec400
Crash State:
  SkROBuffer::Iter::next
  blink::ROBufferSegmentReader::getSomeData
  blink::fill_input_buffer
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=388743:388749

Minimized Testcase (689.10 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97SIH3sn5QqVno-iq59-2KutC2kY4Qrm7Yva6OflW199VgUNwx2hyhOWh9cTmR2Eb8kF7gPSaOAtQ04Z9kf6Iqftbtw3q4caTRuwQYYdNa7oqkd14VICIbVwVz2VPshG_7olfRNziXGTO6nitDbQzVm7J63-7xNUTSxIs29dFYPLcWoIss

Filer: ssamanoori

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink
Labels: -Type-Bug ToolsTestsFindItNoResult M-51 Te-Logged Type-Bug-Regression
Owner: scroggo@chromium.org
Status: Assigned (was: Available)
Through code search file 'SegmentReader.cpp' suspecting the below
https://chromium.googlesource.com/chromium/src/+/d2234904faee943bd987bd38d620096db808efca%5E%21/third_party/WebKit/Source/platform/image-decoders/SegmentReader.cpp

scroggo@ Could you please look into this issue if its related to your change,else please re assign it to an appropriate dev person.
Mergedinto: 605479
Status: Duplicate (was: Assigned)
Project Member

Comment 3 by ClusterFuzz, Apr 22 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5434198067773440

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race READ 8
Crash Address: 0x7d84000ec400
Crash State:
  SkROBuffer::Iter::next
  blink::ROBufferSegmentReader::getSomeData
  blink::fill_input_buffer
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=388743:388749

Minimized Testcase (689.10 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97SIH3sn5QqVno-iq59-2KutC2kY4Qrm7Yva6OflW199VgUNwx2hyhOWh9cTmR2Eb8kF7gPSaOAtQ04Z9kf6Iqftbtw3q4caTRuwQYYdNa7oqkd14VICIbVwVz2VPshG_7olfRNziXGTO6nitDbQzVm7J63-7xNUTSxIs29dFYPLcWoIss

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by bugdroid1@chromium.org, May 25 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/8aefecbfa0b40fb644ca63fd742bd04eb576ba7f

commit 8aefecbfa0b40fb644ca63fd742bd04eb576ba7f
Author: dpranke <dpranke@chromium.org>
Date: Wed May 25 01:43:54 2016

Allow use_debug_fission to be passed to gcc_toolchain().

This is needed so that the nacl_bootstrap toolchains can force it
to be off regardless of the setting for the default toolchains.

TBR=mcgrathr@chromium.org
BUG= 605896 

Review-Url: https://codereview.chromium.org/2011693002
Cr-Commit-Position: refs/heads/master@{#395770}

[modify] https://crrev.com/8aefecbfa0b40fb644ca63fd742bd04eb576ba7f/build/toolchain/gcc_toolchain.gni

Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment