Detailed report: https://clusterfuzz.com/testcase?key=6490507615404032 Fuzzer: ochang_domfuzzer Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Data race WRITE 4 Crash Address: 0x7f206601d198 Crash State: void blink::ContainerNode::insertNodeVector<blink::ContainerNode::AdoptAndAppend blink::ContainerNode::appendChild blink::Node::setTextContent Sanitizer: thread (TSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=456256:456287 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94pCxWephWiDHLu-u7WoZPzTbhXwliWzcw9GuX5ajvvh2pmevFaQ9bK8kag3RjN2TpQ3J7Ue88IocTjALruBlDaGLPV_rzVBwbYi2h-e5Kl0FR6YA_PJO7frO-6g3Eixw8HNLtcT0fTiXNvP7mxKOJswlxj7Ft0RFvHd8cGv2sJROm1FykSQ8fpouv61t2Hmn7vrEqcSygQn8S1eRWzbLpiklJDt0-jF4TFYfbuKA6shzPI8atkLJRUK-VvtDqNuLSDNEJ_H_J12wncYmnj9cqGxYVoa--VnDcdZeqvUW3a1Sc_wo5apNShrECZcnl2bQWVj0WAwi14MgWsBluk6vFdNP453xUoqxl9h603w5dXNsswhAY?testcase_id=6490507615404032 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
ClusterFuzz has detected this issue as fixed in range 458081:458090. Detailed report: https://clusterfuzz.com/testcase?key=6490507615404032 Fuzzer: ochang_domfuzzer Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Data race WRITE 4 Crash Address: 0x7f206601d198 Crash State: void blink::ContainerNode::insertNodeVector<blink::ContainerNode::AdoptAndAppend blink::ContainerNode::appendChild blink::Node::setTextContent Sanitizer: thread (TSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=456256:456287 Fixed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=458081:458090 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94pCxWephWiDHLu-u7WoZPzTbhXwliWzcw9GuX5ajvvh2pmevFaQ9bK8kag3RjN2TpQ3J7Ue88IocTjALruBlDaGLPV_rzVBwbYi2h-e5Kl0FR6YA_PJO7frO-6g3Eixw8HNLtcT0fTiXNvP7mxKOJswlxj7Ft0RFvHd8cGv2sJROm1FykSQ8fpouv61t2Hmn7vrEqcSygQn8S1eRWzbLpiklJDt0-jF4TFYfbuKA6shzPI8atkLJRUK-VvtDqNuLSDNEJ_H_J12wncYmnj9cqGxYVoa--VnDcdZeqvUW3a1Sc_wo5apNShrECZcnl2bQWVj0WAwi14MgWsBluk6vFdNP453xUoqxl9h603w5dXNsswhAY?testcase_id=6490507615404032 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Comment 1 by tkent@chromium.org
, Mar 13 2017Status: Duplicate (was: Untriaged)