Direct-leak in v8::internal::MemoryChunk::AllocateLocalTracker |
||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5176568085479424 Fuzzer: libfuzzer_radamsa_web_icon_sizes_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: Direct-leak Crash Address: Crash State: v8::internal::MemoryChunk::AllocateLocalTracker v8::internal::Page::Initialize v8::internal::SemiSpace::Commit Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=423769:423794 Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97ttwqJ8M7UXKA09k2NRjquuaNfBs9AzGuIbMFSDXAnBRA6J4ydVX-vyxkmlPEd4O6K1wVWs3VYc9JtR5Ho82A7m30lQPzjcamcmFqcD9_T-zAGhMuDekYClp5gdTWuAo4hYniAUCKucheVfRcbemr50ThGUg?testcase_id=5176568085479424 Issue manually filed by: ajha See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Oct 21 2016
Igor, please take a look.
,
Oct 31 2016
mlippautz @ could you please look into this.please feel free to re-assigned back if needed. thanks in advance !
,
Nov 2 2016
,
Nov 2 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/588641f242f4adf5240ca02d95c945afa40ab6c9 commit 588641f242f4adf5240ca02d95c945afa40ab6c9 Author: mlippautz <mlippautz@chromium.org> Date: Wed Nov 02 13:10:20 2016 [heap] Fix Unmapper::TearDown to include delayed chunks Delayed chunks in the unmapper are chunks that should be unmapped but could potentially still be accessed by the sweeper (page header), hence their unmapping is delayed. During TearDown, however, we need to properly unmap those pages, i.e., check that they can now be unmapped (should always hold) and properly unmap them. BUG= chromium:656537 R=ulan@chromium.org Review-Url: https://codereview.chromium.org/2472573003 Cr-Commit-Position: refs/heads/master@{#40698} [modify] https://crrev.com/588641f242f4adf5240ca02d95c945afa40ab6c9/src/heap/spaces.cc [modify] https://crrev.com/588641f242f4adf5240ca02d95c945afa40ab6c9/src/heap/spaces.h
,
Nov 2 2016
Couldn't reproduce (also CF flagged it as non-reproducable) but found a corner case that could result in this LSan failure.
,
Nov 20 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by ajha@chromium.org
, Oct 17 2016Components: Blink>JavaScript
Labels: M-56 Te-Logged