New issue
Advanced search Search tips

Issue 625556 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 625549
Owner:
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in v8::internal::RootMarkingVisitor::MarkObjectByPointer

Project Member Reported by ClusterFuzz, Jul 4 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5516141023985664

Fuzzer: mbarbella_js_mutation
Job Type: linux_asan_d8_v8_mipsel_dbg
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000e8
Crash State:
  v8::internal::RootMarkingVisitor::MarkObjectByPointer
  v8::internal::RootMarkingVisitor::VisitPointers
  v8::internal::JavaScriptFrame::Iterate
  
Regressed: V8: r37484:37485

Minimized Testcase (1.34 Kb): https://cluster-fuzz.appspot.com/download/AMIfv969EcmWSFMtTHOLm7Iuhwfbh4hbAy2Ak-zTpUolrHIDvpyXWQLZ3G9HV2A2JCWWFc64gPhZ5arIXirS7AVAtT3viR6_ikclcEZPMFjxZKQoA7t2YewXBKD5ietFQ5CyT_BMI46e6BCM7RNLx9dFAm6zHNpqew?testcase_id=5516141023985664

Filer: ishell

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
 Issue 625548  has been merged into this issue.
 Issue 625552  has been merged into this issue.
 Issue 625553  has been merged into this issue.
 Issue 625555  has been merged into this issue.
Cc: danno@chromium.org hablich@chromium.org
Owner: adamk@chromium.org
Status: Assigned (was: Available)
CF points to ab529234853a1768642f8f6c907aaaa5ea8b19bf but most likely it's a dupe of  issue 625549 .
Project Member

Comment 6 by ClusterFuzz, Jul 4 2016

ClusterFuzz has detected this issue as fixed in range 37498:37499.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5516141023985664

Fuzzer: mbarbella_js_mutation
Job Type: linux_asan_d8_v8_mipsel_dbg
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000e8
Crash State:
  v8::internal::RootMarkingVisitor::MarkObjectByPointer
  v8::internal::RootMarkingVisitor::VisitPointers
  v8::internal::JavaScriptFrame::Iterate
  
Regressed: V8: r37484:37485
Fixed: V8: r37498:37499

Minimized Testcase (1.34 Kb): https://cluster-fuzz.appspot.com/download/AMIfv969EcmWSFMtTHOLm7Iuhwfbh4hbAy2Ak-zTpUolrHIDvpyXWQLZ3G9HV2A2JCWWFc64gPhZ5arIXirS7AVAtT3viR6_ikclcEZPMFjxZKQoA7t2YewXBKD5ietFQ5CyT_BMI46e6BCM7RNLx9dFAm6zHNpqew?testcase_id=5516141023985664

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Mergedinto: 625549
Status: Duplicate (was: Assigned)
Yes, it was a dupe.
Project Member

Comment 8 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment