New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 627203 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Jul 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

(map()->unused_property_fields())==(actual_unused_property_fields - JSObject::kF

Project Member Reported by ClusterFuzz, Jul 11 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5383336658993152

Fuzzer: meacer_chromebot_extensions
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  (map()->unused_property_fields())==(actual_unused_property_fields - JSObject::kF
  [vdso]
  v8::base::OS::Abort
  V8_Fatal
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=404238:404340

Minimized Testcase (18.10 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94q_MMRQRLKcebNw9kK71ta_yolpfbor1NPIKe9luYeKuttejC_bAGSpmF2iIuYJiVrKbHZjr8c_le1okSSDWH1wIRoTg6S-oUKLyCLbMV6ZSRYS_wMW-IDn1ymcf-KWQxp7W53FkdOdRNQtVDDMf3CTfArAF2W9FGXNalFiM79A-GLWI4?testcase_id=5383336658993152

Filer: mmohammad

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: littledan@chromium.org
Status: Assigned (was: Available)
https://chromium.googlesource.com/v8/v8/+/0ff7b4830c82b9e6a9f14d375b05ee64009e1d01

Last updated by littledan  @ months ago ,  please have a look and reassign if needed.

Thank you.
Cc: littledan@chromium.org
Owner: mmohammad@chromium.org
I'm not sure what you're saying was last updated months ago.

I cannot reproduce this issue, and the repro case looks very strange--no JavaScript, just a page redirect. I'm wondering if there are Clusterfuzz issues here that make the reproduction different from the original. I'm also not sure what's pointing to my patch, as it does not seem to be in the linked V8 range https://chromium.googlesource.com/v8/v8/+log/b70ce97a8692ddc60102e481a502de32cd4b305e..8e8649093cb16688093b49a7046de3d67b8f3068?pretty=fuller . Could you look at this further from an infrastructure perspective, mmohammad?
let me re- check and update the same. Thank you !
Project Member

Comment 4 by ClusterFuzz, Jul 14 2016

ClusterFuzz has detected this issue as fixed in range 405052:405102.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5383336658993152

Fuzzer: meacer_chromebot_extensions
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  (map()->unused_property_fields())==(actual_unused_property_fields - JSObject::kF
  [vdso]
  v8::base::OS::Abort
  V8_Fatal
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=404238:404340
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=405052:405102

Minimized Testcase (18.10 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94q_MMRQRLKcebNw9kK71ta_yolpfbor1NPIKe9luYeKuttejC_bAGSpmF2iIuYJiVrKbHZjr8c_le1okSSDWH1wIRoTg6S-oUKLyCLbMV6ZSRYS_wMW-IDn1ymcf-KWQxp7W53FkdOdRNQtVDDMf3CTfArAF2W9FGXNalFiM79A-GLWI4?testcase_id=5383336658993152

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Jul 14 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment