New issue
Advanced search Search tips

Issue 643197 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Sep 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Data race in base::internal::WeakReferenceOwner::~WeakReferenceOwner

Project Member Reported by ClusterFuzz, Sep 1 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5742213160239104

Fuzzer: inferno_flicker
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race READ 8
Crash Address: 0x7d4c00005578
Crash State:
  base::internal::WeakReferenceOwner::~WeakReferenceOwner
  media::FFmpegDemuxer::~FFmpegDemuxer
  media::FFmpegDemuxer::~FFmpegDemuxer
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=415049:415582

Minimized Testcase (8201.11 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94q6prYMnag9YGP2lp_p5cTr2nOoea9RLYupAQ_4RwjG7SPO5d3J3ytWgEo32l9ai2kD7H7r7po1jIEHD6DD15kIOH16Pv6mrHEm29Xf-F0vYaso3_lmnds0yIFKErwdOiT4qP9W4kMeOHGnAP2oTdlVduZknNLERImYgBKito4rk8QPwU?testcase_id=5742213160239104

Issue manually filed by: msrchandra

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink>Scheduling Tools>Test>FindIt>CorrectResult
Labels: -Type-Bug Findit-for-crash Te-Logged Type-Bug-Regression
Owner: panicker@chromium.org
Status: Assigned (was: Untriaged)
Assigning to the concern owner from Find it. Below are the results,

Suspected CLs	The result is a list of CLs that change the crashed files.

Author: panicker
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/d9caeb1b95bbdfab5aa7688e6ce143f018f58178
Time: Tue Aug 30 03:41:19 2016
Lines 234 of file task_queue_manager.cc which potentially caused crash are changed in this cl (frame #7, "blink::scheduler::TaskQueueManager::DoWork").
Minimum distance from crash line to modified line: 0. (file: task_queue_manager.cc, crashed on: 234, modified: 234).

Suspected Project: chromium
Suspected Component: Blink>Scheduling

@panicker -- Could you please look into the issue, pardon me if it has nothing to do with your changes and if possible please assign it to the concern owner.
Thank You.

Project Member

Comment 2 by ClusterFuzz, Sep 2 2016

ClusterFuzz has detected this issue as fixed in range 415740:415887.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5742213160239104

Fuzzer: inferno_flicker
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race READ 8
Crash Address: 0x7d4c00005578
Crash State:
  base::internal::WeakReferenceOwner::~WeakReferenceOwner
  media::FFmpegDemuxer::~FFmpegDemuxer
  media::FFmpegDemuxer::~FFmpegDemuxer
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=415049:415582
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=415740:415887

Minimized Testcase (8201.11 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94q6prYMnag9YGP2lp_p5cTr2nOoea9RLYupAQ_4RwjG7SPO5d3J3ytWgEo32l9ai2kD7H7r7po1jIEHD6DD15kIOH16Pv6mrHEm29Xf-F0vYaso3_lmnds0yIFKErwdOiT4qP9W4kMeOHGnAP2oTdlVduZknNLERImYgBKito4rk8QPwU?testcase_id=5742213160239104

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Sep 2 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment