Issue metadata
Sign in to add a comment
|
Data race in blink::Document::BaseURLForOverride |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5890376817967104 Fuzzer: inferno_layout_test_unmodified Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Data race READ 4 Crash Address: 0x7b0800011168 Crash State: blink::Document::BaseURLForOverride blink::Document::CompleteURL blink::Document::VirtualCompleteURL Sanitizer: thread (TSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=441524:441984 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96L6XMsIvk92vy1Vfnu_nlsMG8xt6lafvgrTNWhKBoLbuGW0g7NCqXch2SGoE1bVrhUAN9YJcW4b0ouLUVuBt8C-lF-2jAsJjb-HCoRW7nP4eiAjZnWY6AtsSEWvZeo9UgMAAuU-3SHZVAqDrcSOzaWBsfI_PW7bEm4EzHqSsIRAALTlz1DNZ3uf3Z6r1o1lJ-YMn--fm8czbVCAh3XzrY_b6xoX2gBo3AYg3bdIsWawONZCP_9Mhu9WeV89rg5ui0hobxxJ_tltDS_gxu19XinEeJ6UbW6-gXfqjzT5AJ3ibBtONnTb7QlHasN7HddX-tI4ymerfglbcRE7VsM102eSObSz5eBHnG8Na6DavBm5lijR0A?testcase_id=5890376817967104 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 17 2017
Assigning to concern owner from Predator results -- The result is a list of CLs that change the crashed files. Author: nasko Project: chromium Changelist: https://chromium.googlesource.com/chromium/src/+/25eb1046e8317b6cf33fb0d831857e80c29cffcc Time: Thu Jan 05 01:41:36 2017 File Document.cpp is changed in this cl (and is part of stack frame #2, "blink::Document::CompleteURL"; frame #3, "non-virtual thunk to blink::Document::VirtualCompleteURL") Minimum distance from crash line to modified line: 91. (file: Document.cpp, crashed on: 3346, modified: 3437). @nasko -- Could you please look into the issue, kindly re-assign if this is not related to your changes. Thank You.
,
Apr 19 2017
My CL was just adding a prefix to some code, which does not change behavior at all. I'm going to make it Untriaged and unassign myself.
,
Apr 21 2017
,
Apr 21 2017
,
Apr 21 2017
Recently I fixed some threading issues in workers, so before taking a close look, I scheduled a fuzzer task to check if this was already fixed.
,
May 12 2017
> I scheduled a fuzzer task to check if this was already fixed. nhiroki@: NextAction passed. It looks like ClsterFuzz still thinks this is reproducible.
,
May 24 2017
ClusterFuzz has detected this issue as fixed in range 473960:473969. Detailed report: https://clusterfuzz.com/testcase?key=5890376817967104 Fuzzer: inferno_layout_test_unmodified Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Data race READ 4 Crash Address: 0x7b0800011168 Crash State: blink::Document::BaseURLForOverride blink::Document::CompleteURL blink::Document::VirtualCompleteURL Sanitizer: thread (TSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=441524:441984 Fixed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=473960:473969 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5890376817967104 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 24 2017
ClusterFuzz testcase 5890376817967104 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jun 1 2017
The NextAction date has arrived: 2017-06-01 |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by tkent@chromium.org
, Apr 14 2017