New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 635735 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Oct 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in v8::internal::HeapObject::SizeFromMap

Project Member Reported by ClusterFuzz, Aug 9 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6106503536967680

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000003
Crash State:
  v8::internal::HeapObject::SizeFromMap
  v8::internal::PagedSpace::Verify
  v8::internal::Heap::Verify
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95_TJ2eC0Kg_ceTv0A5uHGIapwLUk1_AyOoBXI2IUVTGtgy9sDwuceH12I87FqV6RKyIMrXPiiuA0ALNANoHMjQSx490BOGygfApfZFg4CcVmd282fA5soAcRmsDwS9gV4y9Fg7aSpHOh0kaxJXzIWTTiyTng?testcase_id=6106503536967680


Issue manually filed by: nyerramilli

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: nyerramilli@chromium.org
Components: Tools>Test>FindIt>WrongResult Blink>JavaScript
Labels: findit-wrong Te-Logged M-53
Status: Available (was: Untriaged)
requesting V8 team to check the issue and update-

providing Findit results for internal purpose:

Suspected CLs	Regression information is not available. The result is the blame information.

Author: hpayer@chromium.org
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/c85cc472e71583a8d93980fd727165677bc94057
Time: Wed Apr 09 08:20:10 2014
The CL last changed line 139 of file atomicops_internals_x86_gcc.h, which is stack frame 0.

Author: hpayer@chromium.org
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/728614daf92c8a4f3ea91451d9341c2731957273
Time: Wed Apr 09 09:50:25 2014
The CL last changed line 4389 of file objects-inl.h, which is stack frame 1.

Author: vitalyr@chromium.org
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/b5bbf957a859c44b2a108b3bb60443b18516dbdd
Time: Wed Aug 18 13:00:38 2010
The CL last changed line 4447 of file objects-inl.h, which is stack frame 2.

Author: christian.plesner.hansen
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/43d26ecc3563a46f62a0224030667c8f8f3f6ceb
Time: Thu Jul 03 15:10:15 2008
The CL last changed line 1427 of file objects-inl.h, which is stack frame 3.

Author: mlippautz
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/35720342c3a562b57413a257f3457da5cf8ee644
Time: Mon Jun 27 11:34:10 2016
The CL last changed line 76 of file spaces-inl.h, which is stack frame 4.

Author: mstarzinger
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/16f96fde6b935c5f9a9d031f5df9809a814242ce
Time: Fri Aug 14 08:48:11 2015
The CL last changed line 63 of file spaces-inl.h, which is stack frame 5.

Author: vegorov@chromium.org
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/ac36cb4504409229002a2bf3845b0f81b08a94e4
Time: Mon Sep 19 18:36:47 2011
The CL last changed line 1348 of file spaces.cc, which is stack frame 6.

Suspected Project: chromium-v8
Suspected Component: Blink>JavaScript

Status: Untriaged (was: Available)
Cc: ishell@chromium.org
Cc: u...@chromium.org
Components: -Blink>JavaScript Blink>JavaScript>GC
Status: Available (was: Untriaged)
Project Member

Comment 5 by ClusterFuzz, Oct 5 2016

ClusterFuzz has detected this issue as fixed in range 422375:422396.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6106503536967680

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000003
Crash State:
  v8::internal::HeapObject::SizeFromMap
  v8::internal::PagedSpace::Verify
  v8::internal::Heap::Verify
  
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=422375:422396

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95_TJ2eC0Kg_ceTv0A5uHGIapwLUk1_AyOoBXI2IUVTGtgy9sDwuceH12I87FqV6RKyIMrXPiiuA0ALNANoHMjQSx490BOGygfApfZFg4CcVmd282fA5soAcRmsDwS9gV4y9Fg7aSpHOh0kaxJXzIWTTiyTng?testcase_id=6106503536967680


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Oct 5 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Components: -Tools>Test>FindIt>WrongResult
Labels: Test-Predator-Wrong
Project Member

Comment 8 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment