New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 658426 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Oct 2016
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in v8::base::OS::Abort

Project Member Reported by ClusterFuzz, Oct 21 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6078497295695872

Fuzzer: libfuzzer_v8_wasm_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000001d391f8
Crash State:
  v8::base::OS::Abort
  V8_Fatal
  v8::internal::wasm::WasmDecoder::OpcodeLength
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=426478:426526

Minimized Testcase (0.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94Dm0B5erdIfG82RlYSxs1EzPIPsWYTCT-y48jhjG_-xHZt0R1OPk5SPhu2DjTiwF5LvlNq4n8cE4qs4_X2sS345a4K0_ze0mG_mqCBTSKBn1P9IKkbXTAKT0aRfxs5mNvxf2udJdMHPL8PTzR-U5W34iGVxw?testcase_id=6078497295695872

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Owner: aseemgarg@chromium.org
Status: Assigned (was: Untriaged)
aseemgarg@ could you please look into this.please feel free to re-assigned back if needed. thanks in advance !

Author: aseemgarg
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/cf9ee0ec6c3768bf7f47363056169ce0624348ef
Time: Thu Oct 20 00:19:33 2016
Lines 341-346 of file ast-decoder.cc which potentially caused crash are changed in this cl (frame #2, "v8::internal::wasm::WasmDecoder::OpcodeLength").
Minimum distance from crash line to modified line: 0. (file: ast-decoder.cc, crashed on: 341, modified: 341).

Suspected Project: chromium-v8
Suspected Component: Blink>JavaScript
Status: Fixed (was: Assigned)
Project Member

Comment 4 by ClusterFuzz, Oct 27 2016

ClusterFuzz has detected this issue as fixed in range 427617:427664.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6078497295695872

Fuzzer: libfuzzer_v8_wasm_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000001d391f8
Crash State:
  v8::internal::wasm::WasmDecoder::OpcodeLength
  v8::internal::wasm::WasmFullDecoder::AnalyzeLoopAssignment
  v8::internal::wasm::WasmFullDecoder::PrepareForLoop
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=426478:426526
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=427617:427664

Minimized Testcase (0.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96NbSI-_wq6vlzRuS1FRksCLZ0bgYARWcNbm4lg1AtkpBEL_zm_aIyCj0xpChFhnHWzDiwMkIcD6CHi1E2mrlHNNE_ZrHAc4xHfqM336wOK8BcfsJy1Jnijeyd3wqe_6sP7FDgxgt-RRREqnCaA9ZOMEfLP5w?testcase_id=6078497295695872

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment