Data race in blink::WorkerOrWorkletScriptController::ExecutionState::~ExecutionState |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6293988084809728 Fuzzer: inferno_layout_test_unmodified Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Data race READ 4 Crash Address: 0x7d1000024940 Crash State: blink::WorkerOrWorkletScriptController::ExecutionState::~ExecutionState blink::WorkerOrWorkletScriptController::evaluate blink::WorkerThread::initialize Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=396083:396125 Minimized Testcase (1.32 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94gQCZHIatBuvW68LZLnt6WlMDpUVVmx9kc3phXaoLjriALUDkqKFQ3lNiUrvZNOPvlpMHoKd5y67tv5EUP_f-tAIu7ARqb3GtaqRg-OP1-fA-8eFLTf6t8OCGvLv89F1KLRRs2KR9ZPgOQ2RINpr3v2Am8Rg Filer: manoranjanr See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
May 27 2016
As far as I can tell from the stack traces, this is not a problem with Strings in itself, but rather something about a WorkerOrWorkletScriptController thread manages their lifetime. Possibly dcf3826071f4aa88ab, reassiging to dgozman.
,
May 31 2016
,
Jun 2 2016
ClusterFuzz has detected this issue as fixed in range 397130:397162. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6293988084809728 Fuzzer: inferno_layout_test_unmodified Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Data race READ 4 Crash Address: 0x7d1000024940 Crash State: blink::WorkerOrWorkletScriptController::ExecutionState::~ExecutionState blink::WorkerOrWorkletScriptController::evaluate blink::WorkerThread::initialize Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=396083:396125 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=397130:397162 Minimized Testcase (1.32 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94gQCZHIatBuvW68LZLnt6WlMDpUVVmx9kc3phXaoLjriALUDkqKFQ3lNiUrvZNOPvlpMHoKd5y67tv5EUP_f-tAIu7ARqb3GtaqRg-OP1-fA-8eFLTf6t8OCGvLv89F1KLRRs2KR9ZPgOQ2RINpr3v2Am8Rg See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by manoranj...@chromium.org
, May 26 2016Labels: Te-Logged
Owner: drott@chromium.org
Status: Assigned (was: Available)