New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 648740 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Sep 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

arguments() != nullptr == migrate_to->arguments() != nullptr in scopes.cc

Project Member Reported by ClusterFuzz, Sep 20 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6589021549756416

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8_ignition_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  arguments() != nullptr == migrate_to->arguments() != nullptr in scopes.cc
  
Regressed: V8: r39229:39230

Minimized Testcase (5.56 Kb): https://cluster-fuzz.appspot.com/download/AMIfv961cnP197XiQexcrLls3tESBJOu__hRap10ELK6XQxtG4xGDDTWtaS7Gr-jo1TkNqCTyP7xw7X9oCsY-w6P_I4nZNO7uXR9_3C-WJbY-5XqWJOBPPR3lmsPyIqTQiyNbrieIQ_iVSX-l_IzpoEdPBGRP-UlAQ?testcase_id=6589021549756416

Issue manually filed by: mmohammad

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: verwa...@chromium.org
Status: Assigned (was: Untriaged)
This might be a suspected :

https://chromium.googlesource.com/v8/v8/+/58524d6df343911c2ea1f3793718cb012f7e813c%5E%21/src/ast/scopes.cc


verwaest @ could you please look into this.please feel free to re-assigned back if needed. thanks in advance !
Cc: l...@chromium.org adamk@chromium.org
Regression range points to 7a38b927c89f54d27ee0ce5c297f06b9b655373b.

Comment 3 by adamk@chromium.org, Sep 21 2016

Cc: -l...@chromium.org verwa...@chromium.org
Owner: l...@chromium.org
lpy, please take a look

Comment 4 by l...@chromium.org, Sep 21 2016

Status: Started (was: Assigned)
Project Member

Comment 5 by ClusterFuzz, Sep 23 2016

ClusterFuzz has detected this issue as fixed in range 39641:39642.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6589021549756416

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8_ignition_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  arguments() != nullptr == migrate_to->arguments() != nullptr in scopes.cc
  
Regressed: V8: r39229:39230
Fixed: V8: r39641:39642

Minimized Testcase (5.56 Kb): https://cluster-fuzz.appspot.com/download/AMIfv961cnP197XiQexcrLls3tESBJOu__hRap10ELK6XQxtG4xGDDTWtaS7Gr-jo1TkNqCTyP7xw7X9oCsY-w6P_I4nZNO7uXR9_3C-WJbY-5XqWJOBPPR3lmsPyIqTQiyNbrieIQ_iVSX-l_IzpoEdPBGRP-UlAQ?testcase_id=6589021549756416

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Sep 23 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Started)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment