Issue metadata
Sign in to add a comment
|
!done() || handler_ == __null in src/frames.cc |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5430035938279424 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !done() || handler_ == __null in src/frames.cc Regressed: V8: r34395:34396 Minimized Testcase (9.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv9622TpjzBBfvvt5wYkWrfeQ0WEWhCqrauK2yAXGC20k2pGP4i9_EitWh1GUcY-Suah9c842Ov9N-idNCKov1AjabAScc4nbvhPdV1SgxCgg85iem_4ppvaArxFPN5s0Mdp0IPjDXtAImw3hl2m-K4ohvmuWQg Filer: hablich See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 16 2016
,
Mar 17 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6446014277353472 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x000000000000 Crash State: v8::internal::StackFrame::ComputeType v8::internal::StackFrameIterator::Advance v8::internal::Isolate::PrintStack Regressed: V8: r34395:34396 Minimized Testcase (8.79 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95huJOuF725FSHs1gEekRDcwuUFe3NkgwayyEP5cXiIM45QIGn-H5QLJZdCFzP30EyxcliIlSfWtKsIQAnImFvvUH4nvT3adDKvb9eoE97rW-I3Kbn9vk0erR2biAD2PjEEd9XJajqTQ47l5fTc6ZZFhPAK-A Filer: jkummerow See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 17 2016
Jaro: thanks for taking over here. As discussed, it looks like a missing deopt point in TurboFan: [compiling method 0x107d98012c89 <JS Function assertEquals (SharedFunctionInfo 0x365b79dc539)> using TurboFan] [optimizing 0x107d98012c89 <JS Function assertEquals (SharedFunctionInfo 0x365b79dc539)> - took 47.347, 0.000, 0.000 ms] [couldn't find pc offset for node=-1] [method: assertEquals] Danno: FYI; I hear you've been looking into a similar issue. Bumping back to P1 because it reproduces with ToT.
,
Mar 17 2016
Yes, the bug is here https://bugs.chromium.org/p/chromium/issues/detail?id=595259. Don't know if it's a dupe, and it's not a missing deopt point, it's in fact a problem identifying potential deopt points in TF, which seems to create entries in the Deopt info table of a format that the code doesn't expect.
,
Mar 18 2016
ClusterFuzz has detected this issue as fixed in range 34852:34853. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5430035938279424 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !done() || handler_ == __null in src/frames.cc Regressed: V8: r34395:34396 Fixed: V8: r34852:34853 Minimized Testcase (9.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv9622TpjzBBfvvt5wYkWrfeQ0WEWhCqrauK2yAXGC20k2pGP4i9_EitWh1GUcY-Suah9c842Ov9N-idNCKov1AjabAScc4nbvhPdV1SgxCgg85iem_4ppvaArxFPN5s0Mdp0IPjDXtAImw3hl2m-K4ohvmuWQg See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 18 2016
ClusterFuzz has detected this issue as fixed in range 34867:34868. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6446014277353472 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x000000000000 Crash State: v8::internal::StackFrame::ComputeType v8::internal::StackFrameIterator::Advance v8::internal::Isolate::PrintStack Regressed: V8: r34395:34396 Fixed: V8: r34867:34868 Minimized Testcase (8.79 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95huJOuF725FSHs1gEekRDcwuUFe3NkgwayyEP5cXiIM45QIGn-H5QLJZdCFzP30EyxcliIlSfWtKsIQAnImFvvUH4nvT3adDKvb9eoE97rW-I3Kbn9vk0erR2biAD2PjEEd9XJajqTQ47l5fTc6ZZFhPAK-A See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 21 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by habl...@google.com
, Mar 16 2016Status: Assigned (was: Available)