New issue
Advanced search Search tips

Issue 668517 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug

Blocking:
issue v8:5267



Sign in to add a comment

!data->register_allocation_data()->ExistsUseWithoutDefinition() in pipeline.cc (Shipping escape analysis)

Project Member Reported by ClusterFuzz, Nov 24 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4821146701922304

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8_ignition_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  !data->register_allocation_data()->ExistsUseWithoutDefinition() in pipeline.cc
  
Regressed: V8: r41257:41258

Minimized Testcase (7.92 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95zYKiTJqIdw0lDJtIin3gLjTNThJZccPwRhXTSyBtl-TlmaPaeqgpIK1wSbnv7t1QrNMaP6uBTlCKNmWqTIGT9KDnMc_ScHwvTE5cepEWrpB_5MHPVTJh6W2QHR5iEhF2SGuFzJwvz71MWSW1HYMmAOGat8A?testcase_id=4821146701922304

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: tebbi@chromium.org
Owner: bmeu...@chromium.org
Status: Assigned (was: Untriaged)
Regression range points to 3313394fcffe01fac819bfc2e77854ce14a70ad9.
Blocking: v8:5267
Cc: -tebbi@chromium.org bmeu...@chromium.org
Owner: tebbi@chromium.org
Summary: !data->register_allocation_data()->ExistsUseWithoutDefinition() in pipeline.cc (Shipping escape analysis) (was: !data->register_allocation_data()->ExistsUseWithoutDefinition() in pipeline.cc)
tebbi@ please take a look.
Project Member

Comment 3 by ClusterFuzz, Dec 1 2016

ClusterFuzz has detected this issue as fixed in range 41398:41399.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4821146701922304

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8_ignition_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  !data->register_allocation_data()->ExistsUseWithoutDefinition() in pipeline.cc
  
Regressed: V8: r41257:41258
Fixed: V8: r41398:41399

Minimized Testcase (7.92 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95zYKiTJqIdw0lDJtIin3gLjTNThJZccPwRhXTSyBtl-TlmaPaeqgpIK1wSbnv7t1QrNMaP6uBTlCKNmWqTIGT9KDnMc_ScHwvTE5cepEWrpB_5MHPVTJh6W2QHR5iEhF2SGuFzJwvz71MWSW1HYMmAOGat8A?testcase_id=4821146701922304

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 4 by tebbi@chromium.org, Dec 1 2016

Status: Fixed (was: Assigned)

Sign in to add a comment