Crash in v8::internal::wasm::ThreadImpl::Execute |
||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4621568611450880 Fuzzer: afl_v8_wasm_code_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000083 Crash State: v8::internal::wasm::ThreadImpl::Execute v8::internal::wasm::ThreadImpl::Run v8::internal::wasm::testing::InterpretWasmModule Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=418042:418134 Minimized Testcase (0.25 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94eABihQVbcq5oaY-lwuNcalIV8ZrHed4mBZNACkM-1aJR7__CTMoZtxsmVDgtFbcr5GTCGGwe-e9DJrOIPgLeIaJzUiYTYt_QXWBCJXyJYLf5cdfOOLxybXt4RoohZTDSwAOJSIhDv5vgr5DCC1tOtyqojFQ?testcase_id=4621568611450880 Issue manually filed by: tkonchada See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Sep 15 2016
ClusterFuzz has detected this issue as fixed in range 418554:418622. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4621568611450880 Fuzzer: afl_v8_wasm_code_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000083 Crash State: v8::internal::wasm::ThreadImpl::Execute v8::internal::wasm::ThreadImpl::Run v8::internal::wasm::testing::InterpretWasmModule Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=418042:418134 Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=418554:418622 Minimized Testcase (0.25 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94eABihQVbcq5oaY-lwuNcalIV8ZrHed4mBZNACkM-1aJR7__CTMoZtxsmVDgtFbcr5GTCGGwe-e9DJrOIPgLeIaJzUiYTYt_QXWBCJXyJYLf5cdfOOLxybXt4RoohZTDSwAOJSIhDv5vgr5DCC1tOtyqojFQ?testcase_id=4621568611450880 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 16 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4959037378789376 Fuzzer: afl_v8_wasm_code_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000008 Crash State: v8::internal::wasm::ThreadImpl::Execute v8::internal::wasm::ThreadImpl::Run v8::internal::wasm::testing::InterpretWasmModule Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=418513:418554 Minimized Testcase (0.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97brN2zWxmyqU5bVrldBkh4RmzyiMnJflX3vSsAFFi0qKKzu1mxJN8uGrAvVG56jeS4mwaa_FVP7g2agQErN299u3AXL4vYJxVSW66MUwwIKXQfV8oW59ypl9gKo4sNRNBBH-UpBufWYgze3YtJC3PsD9Sb7Q?testcase_id=4959037378789376 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Sep 17 2016
,
Sep 22 2016
,
Sep 22 2016
Issue 648066 has been merged into this issue.
,
Sep 22 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/813be427913c8506d78184be2a59d70dc42b9f00 commit 813be427913c8506d78184be2a59d70dc42b9f00 Author: ahaas <ahaas@chromium.org> Date: Thu Sep 22 17:11:38 2016 [wasm] Make sure the interpreter only executes preprocessed code. BUG= chromium:646753 R=titzer@chromium.org Review-Url: https://codereview.chromium.org/2365633002 Cr-Commit-Position: refs/heads/master@{#39638} [modify] https://crrev.com/813be427913c8506d78184be2a59d70dc42b9f00/src/wasm/wasm-interpreter.cc
,
Sep 24 2016
ClusterFuzz has detected this issue as fixed in range 420693:420804. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4959037378789376 Fuzzer: afl_v8_wasm_code_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000008 Crash State: v8::internal::wasm::ThreadImpl::Execute v8::internal::wasm::ThreadImpl::Run v8::internal::wasm::testing::InterpretWasmModule Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=418513:418554 Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=420693:420804 Minimized Testcase (0.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97brN2zWxmyqU5bVrldBkh4RmzyiMnJflX3vSsAFFi0qKKzu1mxJN8uGrAvVG56jeS4mwaa_FVP7g2agQErN299u3AXL4vYJxVSW66MUwwIKXQfV8oW59ypl9gKo4sNRNBBH-UpBufWYgze3YtJC3PsD9Sb7Q?testcase_id=4959037378789376 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 24 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by tkonch...@chromium.org
, Sep 14 2016Labels: M-55 Te-Logged
Status: Available (was: Untriaged)