Crash in v8::internal::Invoke |
|||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4684639775490048 Fuzzer: decoder_langfuzz Job Type: linux_asan_chrome_v8_d8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: v8::internal::Invoke v8::internal::Execution::Call v8::Script::Run Regressed: V8: r34384:34400 Minimized Testcase (11.92 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97Th9lUW1Pk_HmO_a82FMq7D0d3XHRnctyh741n_jauerRcrFiXX0DcZPBKz_McCNn7zAO5fL5kkuog7q5AHXV0cjIAfLRkF6FwxgN0Cuqlh820Q91wB6OmksEPV3_e3c5Ckh9-1UhrVk0JmW2PJ8R83Hr2Kw Filer: pucchakayala See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 5 2016
,
Apr 5 2016
Reproduces on TOT, introduced by [turbofan] Move lowering of ObjectIs* nodes to ChangeLowering (https://codereview.chromium.org/1712563002). # # Fatal error in ../src/compiler/scheduler.cc, line 1273 # Check failed: InsideSameDominatorChain(block, data->minimum_block_). # I wasn't able to minimize the test case. Add --turbo to the command line.
,
Apr 5 2016
,
Apr 8 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/03975befe31fbc357928fbdc8cf8cf49533eada1 commit 03975befe31fbc357928fbdc8cf8cf49533eada1 Author: jarin <jarin@chromium.org> Date: Fri Apr 08 08:25:50 2016 [turbofan] Remove some clever-but-wrong bits from select lowering. BUG= chromium:600593 LOG=n R=bmeurer@chromium.org Review URL: https://codereview.chromium.org/1870763003 Cr-Commit-Position: refs/heads/master@{#35347} [modify] https://crrev.com/03975befe31fbc357928fbdc8cf8cf49533eada1/src/compiler/select-lowering.cc [modify] https://crrev.com/03975befe31fbc357928fbdc8cf8cf49533eada1/src/compiler/select-lowering.h [add] https://crrev.com/03975befe31fbc357928fbdc8cf8cf49533eada1/test/mjsunit/compiler/regress-600593.js [delete] https://crrev.com/d72112161d36cbc257e8e7c19f4809495ef97208/test/unittests/compiler/select-lowering-unittest.cc [modify] https://crrev.com/03975befe31fbc357928fbdc8cf8cf49533eada1/test/unittests/unittests.gyp
,
Apr 8 2016
,
Apr 8 2016
,
Apr 12 2016
,
Apr 12 2016
Your change meets the bar and is auto-approved for M51 (branch: 2704)
,
Apr 12 2016
Please merge your change to M51 branch 2704 before 5:00 PM PST tomorrow (Wednesday), so we can take it in for M51 Thursday's dev push.
,
Apr 13 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/8e4f1e953ba1051fa5442dee86381b30f6aab853 commit 8e4f1e953ba1051fa5442dee86381b30f6aab853 Author: Jaroslav Sevcik <jarin@chromium.org> Date: Wed Apr 13 08:15:31 2016 Version 5.1.281.6 (cherry-pick) Merged 03975befe31fbc357928fbdc8cf8cf49533eada1 [turbofan] Remove some clever-but-wrong bits from select lowering. BUG= chromium:600593 LOG=N R=bmeurer@chromium.org Review URL: https://codereview.chromium.org/1877223005 . Cr-Commit-Position: refs/branch-heads/5.1@{#9} Cr-Branched-From: 167dc63b4c9a1d0f0fe1b19af93644ac9a561e83-refs/heads/5.1.281@{#1} Cr-Branched-From: 03953f52bd4a184983a551927c406be6489ef89b-refs/heads/master@{#35282} [modify] https://crrev.com/8e4f1e953ba1051fa5442dee86381b30f6aab853/include/v8-version.h [modify] https://crrev.com/8e4f1e953ba1051fa5442dee86381b30f6aab853/src/compiler/select-lowering.cc [modify] https://crrev.com/8e4f1e953ba1051fa5442dee86381b30f6aab853/src/compiler/select-lowering.h [add] https://crrev.com/8e4f1e953ba1051fa5442dee86381b30f6aab853/test/mjsunit/compiler/regress-600593.js [delete] https://crrev.com/2bb6af5a5c4af649561b9d1806552a6daf75db93/test/unittests/compiler/select-lowering-unittest.cc [modify] https://crrev.com/8e4f1e953ba1051fa5442dee86381b30f6aab853/test/unittests/unittests.gyp
,
Apr 14 2016
As per comment #11, this is already merged to M51. So removing "Merge-Approved-51" label.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||
►
Sign in to add a comment |
|||||||||||
Comment 1 by pucchakayala@chromium.org
, Apr 5 2016Labels: Te-Logged M-51
Owner: jkummerow@chromium.org
Status: Assigned (was: Available)