Fatal error in v8::FromJust |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4731164846981120 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: Fatal error Crash Address: Crash State: v8::FromJust Regressed: V8: r38687:38688 Minimized Testcase (0.87 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95a1miid2BQY8UJA1LoxnO2ra8-xsdSU32UGCb2JzxAuBnK54RQFasF0Y8-5uz5QrVW4_PstqkkyRK35SszDFLF1Imm38PoTkuMFVC8iu9L9vsaT0IdFUPY0ow_OznKE9todfR2aNUV1bvod_WTwViEW00eQg?testcase_id=4731164846981120 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Oct 31 2016
Still reproduces with tip-of-tree. Bisects to (also crashes before that CL but differently) ... commit d0e52555f07a6f01a25114355007bc9095e00f6a Author: bradnelson <bradnelson@chromium.org> Date: Wed Aug 17 10:22:09 2016 -0700 [wasm] Support validation of asm.js modules with != 3 args. Our previous per-arch instantiation thunks for asm.js didn't support modules that had or were called with anything other than 3 arguments. Adding support for this. Addding a runtime test method to check if asm validation succeeded. Adding a test of validation with different argument count combinations. R=mstarzinger@chromium.org TEST=mjsunit/asm/asm-validator.js BUG= https://bugs.chromium.org/p/v8/issues/detail?id=4203 Review-Url: https://codereview.chromium.org/2229723002 Cr-Commit-Position: refs/heads/master@{#38688}
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 17 2017
,
Apr 6 2017
ClusterFuzz has detected this issue as fixed in range 44413:44414. Detailed report: https://clusterfuzz.com/testcase?key=4731164846981120 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: Fatal error Crash Address: Crash State: v8::FromJust Sanitizer: address (ASAN) Regressed: V8: 38687:38688 Fixed: V8: 44413:44414 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv95a1miid2BQY8UJA1LoxnO2ra8-xsdSU32UGCb2JzxAuBnK54RQFasF0Y8-5uz5QrVW4_PstqkkyRK35SszDFLF1Imm38PoTkuMFVC8iu9L9vsaT0IdFUPY0ow_OznKE9todfR2aNUV1bvod_WTwViEW00eQg?testcase_id=4731164846981120 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 6 2017
ClusterFuzz testcase 4731164846981120 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by hablich@chromium.org
, Oct 24 2016Status: Available (was: Untriaged)