New issue
Advanced search Search tips

Issue 631269 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Jul 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Data race in content::ProxyLocaltimeCallToBrowser

Project Member Reported by ClusterFuzz, Jul 25 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6109561882935296

Fuzzer: ochang_domfuzzer
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race WRITE 8
Crash Address: 0x7f004b31afa8
Crash State:
  content::ProxyLocaltimeCallToBrowser
  localtime
  v8::base::OS::DaylightSavingsOffset
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=293188:293491

Minimized Testcase (10.86 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97flyUuvCjWdD6e3QG9MznyIt6iyv75A-DYm5nO8K5q2--ewVMUrHuqCrXp4n8X_CVI0gJhiqiGts_2QsZ7UW4BXqJkM5S6dRNi1guSqSi5i0CdHHt4JUc4VZT1x71tjz_wZAZBExBws0b8tfqtpy9_e94XcA?testcase_id=6109561882935296

Filer: mmohammad

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: ishell@chromium.org mstarzinger@chromium.org
Status: Available (was: Untriaged)

Comment 2 by ishell@chromium.org, Jul 26 2016

Owner: ishell@chromium.org
Status: Assigned (was: Available)

Comment 3 by ishell@chromium.org, Jul 26 2016

The data race happens in a call to localtime(): https://cs.chromium.org/chromium/src/v8/src/base/platform/platform-posix.cc?rcl=0&l=401
Project Member

Comment 4 by ClusterFuzz, Jul 28 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4976671447056384

Fuzzer: inferno_twister
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race WRITE 1
Crash Address: 0x7ff46f6a10d0
Crash State:
  content::ProxyLocaltimeCallToBrowser
  localtime
  v8::base::OS::LocalTimeOffset
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=273715:273845

Minimized Testcase (270.33 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95ZtrXP7e50xoPMbBgh9jVZidCzoe9uSD97Us9Cz0z1IZIJWMR-X3KrSVFOjCKSTgdd8pYKbB4M4_351nJ1mQXw_K_86P0VEPkXMPMo8OqupGgsM9j9gWxTqVjkCCrZicJvIJSNVNarguJn2og2GiLu_O1vCk5SYWIBUfOf6xiDTeTkho8?testcase_id=4976671447056384

Filer: rnimmagadda

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 5 by ClusterFuzz, Jul 29 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6287870000365568

Fuzzer: inferno_twister
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race WRITE 1
Crash Address: 0x7f2d7ff960d3
Crash State:
  content::ProxyLocaltimeCallToBrowser
  localtime
  v8::base::OS::DaylightSavingsOffset
  

Minimized Testcase (6.82 Kb): https://cluster-fuzz.appspot.com/download/AMIfv967dMpLVCUVGByHLyJYQFC0JgsX-gHa9b20lxS-2Ll0044NxfwTtreG683kPFTk2zNVPSqtnW3jH6k5NvqDe5N-siWAg7bQb4NnZWx5YuBoxg0p4Z9UdHR3_W_ijimhua-2hqVUQTyXY1RVz-5_HpOfDCiMfg?testcase_id=6287870000365568

Filer: rnimmagadda

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Gentle Ping.

@ishell: Could you please provide some update on this issue.

Thank you.

Comment 7 by ishell@chromium.org, Jul 29 2016

Cc: jochen@chromium.org
I have a CL that should fix it: https://codereview.chromium.org/2184673002/
Project Member

Comment 8 by bugdroid1@chromium.org, Jul 29 2016

Comment 9 by ishell@chromium.org, Jul 29 2016

Status: Fixed (was: Assigned)
Project Member

Comment 10 by ClusterFuzz, Jul 31 2016

ClusterFuzz has detected this issue as fixed in range 408661:408692.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4976671447056384

Fuzzer: inferno_twister
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race WRITE 1
Crash Address: 0x7ff46f6a10d0
Crash State:
  content::ProxyLocaltimeCallToBrowser
  localtime
  v8::base::OS::LocalTimeOffset
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=273715:273845
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=408661:408692

Minimized Testcase (270.33 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95ZtrXP7e50xoPMbBgh9jVZidCzoe9uSD97Us9Cz0z1IZIJWMR-X3KrSVFOjCKSTgdd8pYKbB4M4_351nJ1mQXw_K_86P0VEPkXMPMo8OqupGgsM9j9gWxTqVjkCCrZicJvIJSNVNarguJn2og2GiLu_O1vCk5SYWIBUfOf6xiDTeTkho8?testcase_id=4976671447056384

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 11 by ClusterFuzz, Jul 31 2016

ClusterFuzz has detected this issue as fixed in range 408661:408692.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6109561882935296

Fuzzer: ochang_domfuzzer
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race WRITE 8
Crash Address: 0x7f004b31afa8
Crash State:
  content::ProxyLocaltimeCallToBrowser
  localtime
  v8::base::OS::DaylightSavingsOffset
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=293188:293491
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=408661:408692

Minimized Testcase (10.86 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97flyUuvCjWdD6e3QG9MznyIt6iyv75A-DYm5nO8K5q2--ewVMUrHuqCrXp4n8X_CVI0gJhiqiGts_2QsZ7UW4BXqJkM5S6dRNi1guSqSi5i0CdHHt4JUc4VZT1x71tjz_wZAZBExBws0b8tfqtpy9_e94XcA?testcase_id=6109561882935296

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 12 by ClusterFuzz, Jul 31 2016

ClusterFuzz has detected this issue as fixed in range 408661:408692.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6287870000365568

Fuzzer: inferno_twister
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race WRITE 1
Crash Address: 0x7f2d7ff960d3
Crash State:
  content::ProxyLocaltimeCallToBrowser
  localtime
  v8::base::OS::DaylightSavingsOffset
  
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=408661:408692

Minimized Testcase (6.82 Kb): https://cluster-fuzz.appspot.com/download/AMIfv967dMpLVCUVGByHLyJYQFC0JgsX-gHa9b20lxS-2Ll0044NxfwTtreG683kPFTk2zNVPSqtnW3jH6k5NvqDe5N-siWAg7bQb4NnZWx5YuBoxg0p4Z9UdHR3_W_ijimhua-2hqVUQTyXY1RVz-5_HpOfDCiMfg?testcase_id=6287870000365568

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 13 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment