!ScriptForbiddenScope::isScriptForbidden() in V8PerIsolateData.cpp |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5640209443323904 Fuzzer: inferno_twister_custom_bundle Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !ScriptForbiddenScope::isScriptForbidden() in V8PerIsolateData.cpp blink::beforeCallEnteredCallback v8::Function::NewInstance Sanitizer: thread (TSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=443258:443393 Minimized Testcase (0.15 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv955lanqAUDGObPOGulLy8-rQXOkvKwCoUX-xWrT03V8dU75oQiwrzyuV3bn0wS8oqsdIRonzDKgAgxVGeiVCY5fwSMl7z4Nh_B8YFFM05G3oib61vAKE22shAHASm18PvKAsvFdyQUhQyFnXtyO--i32thwfQuqTrYETotY2TrR-ciMpxYTBHyaEJecqYhQwGR-VkOYsyUReaQBGeoWxlKl7Urdu9a2b-k1Fwm-hzyJvZTZvCe4vte82zGwv18fUtIoAQjx9XhxxTr3HsbKLP5tYLO8MvjmPlLU6FZ3Bqi7bvmeFTxW9Wrm5tz6yG0ckNG6iNjIpOapEPngLmxkuQGG7g-bmg33xc9ck55QT6YABzJRxTM?testcase_id=5640209443323904 <script> var audio = document.createElement('audio'); audio.play(); document.implementation.createDocument( "", null).adoptNode(audio); </script> Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 16 2017
,
Jan 16 2017
I think it is duplicated of https://bugs.chromium.org/p/chromium/issues/detail?id=676004 or related. As minimum the call stack seems to be similar.
,
Jan 16 2017
,
Jan 21 2017
ClusterFuzz has detected this issue as fixed in range 444758:445138. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5640209443323904 Fuzzer: inferno_twister_custom_bundle Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !ScriptForbiddenScope::isScriptForbidden() in V8PerIsolateData.cpp blink::beforeCallEnteredCallback v8::Function::NewInstance Sanitizer: thread (TSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=443258:443393 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=444758:445138 Minimized Testcase (0.15 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv955lanqAUDGObPOGulLy8-rQXOkvKwCoUX-xWrT03V8dU75oQiwrzyuV3bn0wS8oqsdIRonzDKgAgxVGeiVCY5fwSMl7z4Nh_B8YFFM05G3oib61vAKE22shAHASm18PvKAsvFdyQUhQyFnXtyO--i32thwfQuqTrYETotY2TrR-ciMpxYTBHyaEJecqYhQwGR-VkOYsyUReaQBGeoWxlKl7Urdu9a2b-k1Fwm-hzyJvZTZvCe4vte82zGwv18fUtIoAQjx9XhxxTr3HsbKLP5tYLO8MvjmPlLU6FZ3Bqi7bvmeFTxW9Wrm5tz6yG0ckNG6iNjIpOapEPngLmxkuQGG7g-bmg33xc9ck55QT6YABzJRxTM?testcase_id=5640209443323904 <script> var audio = document.createElement('audio'); audio.play(); document.implementation.createDocument( "", null).adoptNode(audio); </script> See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 21 2017
ClusterFuzz testcase 5640209443323904 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by tkent@chromium.org
, Jan 16 2017