Issue metadata
Sign in to add a comment
|
safe_to_deopt_topmost_optimized_code in deoptimizer.cc |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6600304003121152 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_ignition_v8_arm_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: safe_to_deopt_topmost_optimized_code in deoptimizer.cc Minimized Testcase (0.20 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv9639hhgDk7cclFOB8sU04qgejpOcy01SuCfMPBxDNNJTCNNGThFs76rtINusWo-2NafqLDWGqtUCgDWVb0vhORR1pnNlDWoo3dSLcncdXLndVVt2opaewR3OqArFCm85PKQKCeTTbHTLhKWLktbwO7IOXXtMw?testcase_id=6600304003121152 var __v_16 = {}; eval() function __f_7() { __v_8 = __v_16; __v_8.a = 1; } __v_6 = __f_7(); __v_7 = __f_7(); (function __f_13() { var __v_10 = { *['a']() { } }; __v_7 = __f_7(); })(); Filer: ishell See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by ishell@chromium.org
, Jun 21 2016Status: Duplicate (was: Available)