New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 652606 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Nov 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

m_lineNumber != v8::Message::kNoLineNumberInfo in v8-stack-trace-impl.cc

Project Member Reported by ClusterFuzz, Oct 4 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5758998584492032

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  m_lineNumber != v8::Message::kNoLineNumberInfo in v8-stack-trace-impl.cc
  v8::base::OS::Abort
  V8_Fatal
  v8_inspector::V8StackTraceImpl::Frame::Frame
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=417355:417362

Minimized Testcase (0.12 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95K3xd403AcbcTKGTVr6MzxjHVXjk7R09Ky_GIyrR6mYn1SzNpi9AJiG_k9ue7YHVj40_he2yTggT4ClYGdoHaxm6l-35fHfU6F4iBvOtgO5sb9EOZQMc160n2oEEyc72uC6tcVKg33n4zXgeilJ92Hur6wXA?testcase_id=5758998584492032
<div id=container><svg><script>
    var svgView = document.getElementById("container").childNodes[0].currentView;
</script>


Issue manually filed by: ranjitkan

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: ranjitkan@chromium.org
Components: Tools>Test>FindIt>NoResult
Labels: -Pri-1 -Type-Bug findit-wrong M-55 Te-Logged Pri-2 Type-Bug-Regression
Owner: littledan@chromium.org
Status: Assigned (was: Untriaged)
Findit did not show any suspected CL's

Using code search suspecting the below change could be a possible culprit which could have resulted this crash.

Change URL: https://chromium.googlesource.com/v8/v8/+/f296dad962e452ced1e5396b9ced7203747f7209
Review-Url: https://codereview.chromium.org/2357423002

@littledan: Assigning to you, Request you to please take a look into it. Please help us to reassign if not with respect to your change.

Thanks.!
Components: -Tools>Test>FindIt>NoResult
Project Member

Comment 3 by ClusterFuzz, Nov 15 2016

ClusterFuzz has detected this issue as fixed in range 431862:431874.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5758998584492032

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  m_lineNumber != v8::Message::kNoLineNumberInfo in v8-stack-trace-impl.cc
  v8_inspector::V8StackTraceImpl::Frame::Frame
  v8_inspector::V8StackTraceImpl::create
  v8_inspector::V8StackTraceImpl::capture
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=417355:417362
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=431862:431874

Minimized Testcase (0.12 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95FsdLQXhqvt5ZlA9LibWjYITN7yGyObyJMNJeHrrgBkPCrv1yT3ORJTrLMIAZ1gf9NLz5Rf1fOHEyDBiGT-gaEuxFn_EM6nWtyUKTZ58ZUmkbJvRjYnVdNvINeGjPYame9un67Mx6cYR06VF23OB2f62mj5A?testcase_id=5758998584492032
<div id=container><svg><script>
    var svgView = document.getElementById("container").childNodes[0].currentView;
</script>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Nov 15 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment