Issue metadata
Sign in to add a comment
|
Crash in v8::internal::Isolate::Throw |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6707038798479360 Fuzzer: libfuzzer_v8_serialized_script_value_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x7f69acbc19e8 Crash State: v8::internal::Isolate::Throw v8::internal::ValueDeserializer::ReadObjectUsingEntireBufferForLegacyFormat v8::ValueDeserializer::ReadValue Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=424448:424514 Minimized Testcase (0.06 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96nrQSqZLJC-m5WqwyczQrwVc3uugACBqQtWbQLSc66hE5DkmASf8mBOP0g3UyIzwuucSBEvA70xBEkP2MrMe2hyt6HtlBTS98aX71KtLRBvtjlRhcFdFlP85fWbnNwmtUukmQ3RfBAJpxGPmD-e4I-sWbzxw?testcase_id=6707038798479360 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Nov 11 2016
Jochen, if you aren't a good person to look at this, feel free to re-assign.
,
Nov 12 2016
,
Nov 14 2016
,
Nov 14 2016
Yeah, I think I just forgot to account for the fact that setting properties in the legacy path could throw an exception early. Seems straightforward.
,
Nov 15 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/054e17796df10ed65e0381691ab092794f9aee2e commit 054e17796df10ed65e0381691ab092794f9aee2e Author: jbroman <jbroman@chromium.org> Date: Tue Nov 15 15:16:20 2016 ValueSerializer: Don't throw an exception after SetPropertiesFromKeyValuePairs fails. It always throws an exception in the cases that it fails, so throwing another doesn't help things. BUG= chromium:664416 Review-Url: https://codereview.chromium.org/2495393002 Cr-Commit-Position: refs/heads/master@{#40999} [modify] https://crrev.com/054e17796df10ed65e0381691ab092794f9aee2e/src/value-serializer.cc
,
Nov 18 2016
ClusterFuzz has detected this issue as fixed in range 432256:432327. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6707038798479360 Fuzzer: libfuzzer_v8_serialized_script_value_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x7f69acbc19e8 Crash State: v8::internal::Isolate::Throw v8::internal::ValueDeserializer::ReadObjectUsingEntireBufferForLegacyFormat v8::ValueDeserializer::ReadValue Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=424448:424514 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=432256:432327 Minimized Testcase (0.06 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96nrQSqZLJC-m5WqwyczQrwVc3uugACBqQtWbQLSc66hE5DkmASf8mBOP0g3UyIzwuucSBEvA70xBEkP2MrMe2hyt6HtlBTS98aX71KtLRBvtjlRhcFdFlP85fWbnNwmtUukmQ3RfBAJpxGPmD-e4I-sWbzxw?testcase_id=6707038798479360 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 18 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/054e17796df10ed65e0381691ab092794f9aee2e commit 054e17796df10ed65e0381691ab092794f9aee2e Author: jbroman <jbroman@chromium.org> Date: Tue Nov 15 15:16:20 2016 ValueSerializer: Don't throw an exception after SetPropertiesFromKeyValuePairs fails. It always throws an exception in the cases that it fails, so throwing another doesn't help things. BUG= chromium:664416 Review-Url: https://codereview.chromium.org/2495393002 Cr-Commit-Position: refs/heads/master@{#40999} [modify] https://crrev.com/054e17796df10ed65e0381691ab092794f9aee2e/src/value-serializer.cc
,
Nov 18 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by nyerramilli@chromium.org
, Nov 11 2016Components: Infra>Git Blink>JavaScript
Labels: -Pri-1 -Type-Bug Test-Predator-Wrong-CLs M-56 Pri-2 Type-Bug-Regression