New issue
Advanced search Search tips

Issue 702949 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Mar 2017
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Data race in blink::ContainerNode::getElementsByTagName

Project Member Reported by ClusterFuzz, Mar 19 2017

Issue description

Project Member

Comment 1 by ClusterFuzz, Mar 23 2017

ClusterFuzz has detected this issue as fixed in range 458620:458734.

Detailed report: https://clusterfuzz.com/testcase?key=4553331604455424

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race WRITE 8
Crash Address: 0x7f223a3fb3e8
Crash State:
  blink::ContainerNode::getElementsByTagName
  blink::V8Document::getElementsByTagNameMethodCallback
  v8::internal::FunctionCallbackArguments::Call
  
Sanitizer: thread (TSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=457847:457871
Fixed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=458620:458734

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94uoVxSlce3LZssJ_RUEbI-pFNWCII5dPLbaCC8hfjX0XMOUIry6WI09_igdTQmL2oq7lDoJGoOq0qlOoNXwLpl_nFD7G4X-lLyPAWicK8-T3WFdznEvcguAC8CdVYxT9PaEtW8AWS_xgKm95Dsx8RcS-hizBgiq65nb5HDUmMsqq2oYJN_sPfkjeajRM0UsdZp-p3fcC4ve-ETJ_SzfqtoWoX_4yFbgj9fAeglyJq_dTiJ7SlzlYTXBS9mvA9wo5yz8uV7wOfMe-mAXPP3t_R2UaF39DoNMlzkwqc4zt-7zbU_koXDXUoCfab_ZXJ-gQtkP6TtH75mdp-EO9KH_UJF8vksHpXQX1zcjimFrK4BtWenSfZKPaMhCrhgkAUargP48e4vYETyxbVvoMZJ8ZeaYN95Kg?testcase_id=4553331604455424


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 2 by ClusterFuzz, Mar 23 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Untriaged)
ClusterFuzz testcase 4553331604455424 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment