New issue
Advanced search Search tips

Issue 649434 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 648737
Owner:
Closed: Sep 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Fatal error in

Project Member Reported by ClusterFuzz, Sep 22 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5093374216634368

Fuzzer: mbarbella_js_mutation
Job Type: windows_asan_d8
Platform Id: windows

Crash Type: Fatal error
Crash Address: 
Crash State:
  
  V8_Fatal
  v8::internal::TranslatedState::MaterializeAt
  v8::internal::TranslatedValue::GetValue
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_d8&range=419839:420163

Minimized Testcase (0.16 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95fOpvlVRG6fyfBurGp1KPWV1LvbCUjf7sg_5EbQFbsyvytPXI4x5BCN1pWy3nC7Cqc6mdslHyZobs8awkS8uB7R-YWL7oaZwGz7_6KrLHjWlWdKXpa6oaUCC9_wLTe5RJTziDFqJ_ZW39MchcYfBQEUpAy6Q?testcase_id=5093374216634368
function __f_3(str) {
  var __v_3 = "We also try to materalize {" + str + "} when deopting";
  return __v_3.length;
}
%OptimizeFunctionOnNextCall(__f_3);
 __f_3();


Issue manually filed by: mmohammad

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: jarin@chromium.org
Status: Assigned (was: Untriaged)
This might be a suspected :

https://chromium.googlesource.com/v8/v8/+/54188964008a32edea8bd4a76c43313d2710043b%5E%21/src/deoptimizer.cc

jarin @ could you please look into this.please feel free to re-assigned back if needed. thanks in advance !
Mergedinto: 648737
Status: Duplicate (was: Assigned)
I really wish our Windows jobs wouldn't take my regression test from a later version and run it against an earlier version without the fix. This is already fixed by the same CL that added the regression test with was used as the obvious seed for the above repro.
Project Member

Comment 3 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment