Data race in blink::ContainerNode::getElementsByTagName |
||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4553331604455424 Fuzzer: inferno_layout_test_unmodified Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Data race WRITE 8 Crash Address: 0x7f223a3fb3e8 Crash State: blink::ContainerNode::getElementsByTagName blink::V8Document::getElementsByTagNameMethodCallback v8::internal::FunctionCallbackArguments::Call Sanitizer: thread (TSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=457847:457871 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94uoVxSlce3LZssJ_RUEbI-pFNWCII5dPLbaCC8hfjX0XMOUIry6WI09_igdTQmL2oq7lDoJGoOq0qlOoNXwLpl_nFD7G4X-lLyPAWicK8-T3WFdznEvcguAC8CdVYxT9PaEtW8AWS_xgKm95Dsx8RcS-hizBgiq65nb5HDUmMsqq2oYJN_sPfkjeajRM0UsdZp-p3fcC4ve-ETJ_SzfqtoWoX_4yFbgj9fAeglyJq_dTiJ7SlzlYTXBS9mvA9wo5yz8uV7wOfMe-mAXPP3t_R2UaF39DoNMlzkwqc4zt-7zbU_koXDXUoCfab_ZXJ-gQtkP6TtH75mdp-EO9KH_UJF8vksHpXQX1zcjimFrK4BtWenSfZKPaMhCrhgkAUargP48e4vYETyxbVvoMZJ8ZeaYN95Kg?testcase_id=4553331604455424 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 23 2017
ClusterFuzz testcase 4553331604455424 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by ClusterFuzz
, Mar 23 2017