New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 658439 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Mar 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in v8::internal::Isolate::Throw

Project Member Reported by ClusterFuzz, Oct 21 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5813588952612864

Fuzzer: libfuzzer_v8_script_parser_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x0000005f1d48
Crash State:
  v8::internal::Isolate::Throw
  v8::internal::PendingCompilationErrorHandler::ThrowPendingError
  v8::internal::Parser::Internalize
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=415616:415651

Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97T6MC4NgDBPK9XNcDHETPTCmVcZB7wtudWW9AnxCEbVZQ2hKule5DTz3R3qoOLDKTvPzDVT1DQvUo8HgRioq3Ox-HwyFUcwDrk0SUkqvoqW5alWw2ht1Kru5Kfd1s7Ax3fLOAJ0a2FcwH755wv1yieoQxBDw?testcase_id=5813588952612864

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 

Comment 1 by jri@chromium.org, Oct 22 2016

Components: Infra>Client>V8
Owner: jochen@chromium.org
Status: Assigned (was: Untriaged)
jochen @ could you please look into this.please feel free to re-assigned back if needed. thanks in advance 

Comment 3 by jochen@chromium.org, Oct 28 2016

Cc: jri@chromium.org
Components: -Infra>Client>V8 Blink>JavaScript
jri: Infra components are for buildbots. JavaScript is Blink > JavaScript

Comment 4 by jochen@chromium.org, Oct 28 2016

Owner: rossberg@chromium.org
assigning to current CF sheriff
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by ClusterFuzz, Mar 8 2017

ClusterFuzz has detected this issue as fixed in range 455091:455226.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5813588952612864

Fuzzer: libfuzzer_v8_script_parser_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x0000005f1d48
Crash State:
  v8::internal::Isolate::Throw
  v8::internal::PendingCompilationErrorHandler::ThrowPendingError
  v8::internal::Parser::Internalize
  
Sanitizer: address (ASAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=415616:415651
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=455091:455226

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv960ZA6ZFyHTtf10ks-t0TObOCH-OLuuixS1cA8zXqiGn-SRJVL9fUrth3Usl01s8GwufnHuioNGGS_2siq7surOEK3QBSGsdKoh2p4xl1qvDjQXqVEULjFsE1pdXtRm-rAlQRbRWjDR1znXNYn6ATlT2CwZQnjyl-A6bQttb1_APFAdSWWpVa1SfOS2HVMLawk1_oiV8joK4pOZQpJgAnVyP3g3cNkEcz6bWVN7bXSHCt9LNf_Do7nNr-O_efCFk5Q8OFTNQtikHNX0KvzY7TH1lw2NJc_pubt0--rNyKR2b7JxVEXPdUgpkgCheBxFl6tIVfNgcCBANVnhOjL9VWuJnw35C566j7hAlPczTNKkYf8TTvs?testcase_id=5813588952612864


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, Mar 8 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5813588952612864 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment