New issue
Advanced search Search tips

Issue 644263 link

Starred by 2 users

Issue metadata

Status: Verified
Owner:
Closed: Sep 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

Crash in v8_fuzzer::FuzzerSupport::GetIsolate

Project Member Reported by ClusterFuzz, Sep 6 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4900596547321856

Fuzzer: libfuzzer_v8_wasm_code_fuzzer
Job Type: mac_libfuzzer_chrome_asan
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  v8_fuzzer::FuzzerSupport::GetIsolate
  RunOne
  FuzzerDriver
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_libfuzzer_chrome_asan&range=415328:415345

Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96Vt71IuqGdFDTSQmdWL_BmspFu5cTd3vVo5nNV8P5oVJIgL7ItkeDnIayzGxVwxxkSmPexP3ADFaX2BZI2qKXJG9HrcmClF9B8GfTrl9ea2-tj9DBz5ZK-q0yrXPRWRE0kVUs3hJQGXrY-EB71Lciy9Zg3wQ?testcase_id=4900596547321856

Issue manually filed by: ashejole

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Components: Blink>JavaScript
Labels: M-55 Te-Logged ToolsTestsFindItWrongResult
Suspected CLs	Git blame below is NOT necessarily who introduced the crash nor the owner for it. Please check the code before assigning to anyone.(No CL in the regression range changed the crashing files.)

Author: jochen
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/cf0435881c66d8a41b9cd923d9e885065c721ebf
Time: Tue Jan 26 10:38:37 2016
The CL last changed line 78 of file fuzzer-support.cc, which is stack frame 0.

Author: ahaas
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/cb259fbd3938eab94739445d8a9110d08d293f87
Time: Mon Aug 29 13:55:41 2016
The CL last changed line 18 of file wasm-code.cc, which is stack frame 1.

Author: kcc
Project: chromium-libfuzzer
Changelist: https://chromium.googlesource.com/chromium/llvm-project/llvm/lib/Fuzzer.git/+/d6b2224ee4102bbe91c0a59dcb563de2d0ea75f2
Time: Thu Aug 25 01:25:03 2016
The CL last changed line 481 of file FuzzerLoop.cpp, which is stack frame 2.

Author: kcc
Project: chromium-libfuzzer
Changelist: https://chromium.googlesource.com/chromium/llvm-project/llvm/lib/Fuzzer.git/+/d33f707d488e6ac62cb5110f90115d9fe863c99e
Time: Sat Feb 13 17:56:51 2016
The CL last changed line 437 of file FuzzerLoop.cpp, which is stack frame 3.

Author: kcc
Project: chromium-libfuzzer
Changelist: https://chromium.googlesource.com/chromium/llvm-project/llvm/lib/Fuzzer.git/+/d33f707d488e6ac62cb5110f90115d9fe863c99e
Time: Sat Feb 13 17:56:51 2016
The CL last changed line 459 of file FuzzerInternal.h, which is stack frame 4.

Author: aizatsky
Project: chromium-libfuzzer
Changelist: https://chromium.googlesource.com/chromium/llvm-project/llvm/lib/Fuzzer.git/+/c028617f67a20cb5abf3ae798232e9fd188cbdd1
Time: Tue Jun 07 18:16:32 2016
The CL last changed line 404 of file FuzzerLoop.cpp, which is stack frame 5.

Author: kcc
Project: chromium-libfuzzer
Changelist: https://chromium.googlesource.com/chromium/llvm-project/llvm/lib/Fuzzer.git/+/6cc74c5b25683bd077ab02e7f6405b9885b0d31d
Time: Thu Feb 19 18:45:37 2015
The CL last changed line 511 of file FuzzerDriver.cpp, which is stack frame 6.

Suspected Project: chromium-v8
-------------------------------------------
Adding the component  Javascript and leaving as Untriaged, so that it can be looked upon by appropriate dev.

Thank you!
Cc: titzer@chromium.org
Components: -Blink>JavaScript Blink>JavaScript>WebAssembly
Owner: ahaas@chromium.org
Seems your new fuzzer is creating results.
Status: Assigned (was: Untriaged)
Gentle Ping! Do we have any further update on this?

Thank you!

Comment 5 by ahaas@chromium.org, Sep 22 2016

I cannot reproduce this issue on my Linux machine. I will try to find someone with a Mac to reproduce this issue.

Comment 6 by ahaas@chromium.org, Sep 22 2016

Cc: -titzer@chromium.org ahaas@chromium.org
Owner: titzer@chromium.org
Ben, could you please take a look?
Project Member

Comment 7 by ClusterFuzz, Sep 23 2016

ClusterFuzz has detected this issue as fixed in range 420351:420359.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4900596547321856

Fuzzer: libfuzzer_v8_wasm_code_fuzzer
Job Type: mac_libfuzzer_chrome_asan
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  v8_fuzzer::FuzzerSupport::GetIsolate
  RunOne
  FuzzerDriver
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_libfuzzer_chrome_asan&range=415328:415345
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_libfuzzer_chrome_asan&range=420351:420359

Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96Vt71IuqGdFDTSQmdWL_BmspFu5cTd3vVo5nNV8P5oVJIgL7ItkeDnIayzGxVwxxkSmPexP3ADFaX2BZI2qKXJG9HrcmClF9B8GfTrl9ea2-tj9DBz5ZK-q0yrXPRWRE0kVUs3hJQGXrY-EB71Lciy9Zg3wQ?testcase_id=4900596547321856

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, Sep 23 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 9 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment