New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 836224 link

Starred by 3 users

Issue metadata

Status: Archived
Owner: ----
Closed: Nov 8
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Data race in g_closure_unref

Project Member Reported by ClusterFuzz, Apr 24 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5684826859110400

Fuzzer: attekett_surku_fuzzer
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Data race WRITE 8
Crash Address: 0x7b040004cb30
Crash State:
  g_closure_unref
  
Sanitizer: thread (TSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=523888:523922

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5684826859110400

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Apr 24 2018

Components: UI>Browser
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Apr 24 2018

Cc: dschuyler@chromium.org e...@chromium.org timbrown@chromium.org
Labels: Test-Predator-Auto-CC
Automatically adding ccs based on suspected regression changelists:

Remove remaining references to gconf by timbrown@chromium.org - https://chromium.googlesource.com/chromium/src/+/c1829894ac62e37257973d5e5c27d1bffb9888b3

[CR elements] migrate some <content> use to <slot> by dschuyler@chromium.org - https://chromium.googlesource.com/chromium/src/+/27ce4da734ec5534c21cd44fa5d7a26ff4a6189d

Fix dead area after a chrome app is started in --mus. by erg@chromium.org - https://chromium.googlesource.com/chromium/src/+/1672701ad759a71e686f41179cd21bf7991b7365

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label.
Labels: M-67 Test-Predator-Wrong
A gentle ping. Could someone please look into this issue.

Thanks!
Labels: CF-NeedsTriage
Cc: -dschuyler@chromium.org
My CL was just HTML changes. I don't think it's related (or if it is, the change would be highlighting a bug elsewhere (not introducing the bug)).
Labels: -CF-NeedsTriage
erg@, do you have any inputs here?
Project Member

Comment 7 by ClusterFuzz, Sep 9

Labels: -M-67 Fuzz-Blocker ReleaseBlock-Beta M-71
This crash occurs very frequently on linux platform and is likely preventing the fuzzer attekett_surku_fuzzer from making much progress. Fixing this will allow more bugs to be found.

Marking this bug as a blocker for next Beta release.

If this is incorrect, please add ClusterFuzz-Wrong label and remove the ReleaseBlock-Beta label.
Cc: wfh@chromium.org kkaluri@chromium.org sky@chromium.org
erg@/timbrown@ : Could you please look into this issue

CC'ing Reviewers, since authors didn't visited crbug recently.
Cc: -e...@chromium.org -sky@chromium.org thomasanderson@chromium.org
https://chromium.googlesource.com/chromium/src/+/1672701ad759a71e686f41179cd21bf7991b7365 adds a trivial conditional to code that is chromeos specific, so I don't think it's to blame here. I'm removing erg (as he left the company a while back) and myself and adding thomasanderson as he is familiar with linux.
Labels: -ReleaseBlock-Beta ClusterFuzz-Wrong
My change is a nop. It's mostly comment changes, with some label changes and a few lines of dead code removed.

I can't see how any of these changes caused this failure so I'm going to do as per comment #7 and change the labels.
Labels: CF-NeedsTriage
Unable to find actual suspect through code search and also observing no CL's under regression range, hence adding appropriate label and requesting someone from dev team to look in to this issue.

Thanks!
Labels: Hotlist-DesktopUIChecked
Status: Archived (was: Untriaged)
Mass UI Triage, archiving old bugs.
Project Member

Comment 13 by ClusterFuzz, Nov 15

Labels: Needs-Feedback
ClusterFuzz testcase 5684826859110400 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.

Sign in to add a comment