New issue
Advanced search Search tips

Issue 709859 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Apr 2017
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Data race in blink::Document::BaseURLForOverride

Project Member Reported by ClusterFuzz, Apr 10 2017

Issue description

Project Member

Comment 1 by ClusterFuzz, Apr 10 2017

ClusterFuzz has detected this issue as fixed in range 463171:463172.

Detailed report: https://clusterfuzz.com/testcase?key=4598832035004416

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race READ 4
Crash Address: 0x7b0800011208
Crash State:
  blink::Document::BaseURLForOverride
  blink::Document::CompleteURL
  blink::Document::VirtualCompleteURL
  
Sanitizer: thread (TSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=441524:441984
Fixed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=463171:463172

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96X6gTGP300JRjZfEQjz9jztiqDqViGMPsI_qTJDOj9FZa0qfsNyVizyA3LZ9zsukkOv6Z57y55EwUmd8s6UmSGP5U5GWJKMt6rZHLeFg_w1gQ2CE8F4oUkcrODcz8ldd-IWck_cM3f1sQ4jrghyzpUNnguseLPZFwH0rcXLKlsaZImHgIdRzIsCEQfo0vf6a-GmHlslOOtr1_9I0SZAmkkQSEzilAEoyBCG88sUi6xiYc_AR9Py_3omTr5vqQ9IxhBpouFpBR6zryJ-8uUtnU6wnqPPGS-sxPsvwz4oqhQu7UXjJScEJBFgzGTf38c2aYmV8R8Q_FwbTrVGuf0OMjqQ9jTPTExHSHADkb8xirs2elW9vs?testcase_id=4598832035004416


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 2 by ClusterFuzz, Apr 10 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Untriaged)
ClusterFuzz testcase 4598832035004416 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment