New issue
Advanced search Search tips

Issue 668675 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 1
Type: Bug

Blocking:
issue v8:5633



Sign in to add a comment

false in code-generator.cc (Shipping escape analysis)

Project Member Reported by ClusterFuzz, Nov 25 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5806026055221248

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8_ignition_v8_arm_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  false in code-generator.cc
  

Minimized Testcase (9.64 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97H-tHNQb9fXkiloOL3cctUECLoqpEBtUwrBek91HZ51HTXJ7pzjtb8kVsvyEh8BF1aDGtunO5aL0ouOfkqtjgayXF5xcevUrqru6UWTCXfMnEjvgVkp1ISwY2XN8syE-OFh_ap0XZmph7bjAncYPwnmVGnsA?testcase_id=5806026055221248

Issue manually filed by: rossberg

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: jarin@chromium.org mstarzinger@chromium.org
Owner: bmeu...@chromium.org
Status: Assigned (was: Untriaged)
@bmeurer, bisects to shipping escape analysis.
Blocking: v8:5633
Components: -Blink>JavaScript Blink>JavaScript>Compiler
Labels: -OS-Linux OS-All
Summary: false in code-generator.cc (Shipping escape analysis) (was: false in code-generator.cc)
Cc: bmeu...@chromium.org
Owner: tebbi@chromium.org
Tobias, please take a look. Thanks.
Project Member

Comment 4 by ClusterFuzz, Dec 1 2016

ClusterFuzz has detected this issue as fixed in range 41398:41399.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5806026055221248

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8_ignition_v8_arm_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  false in code-generator.cc
  
Regressed: V8: r41257:41258
Fixed: V8: r41398:41399

Minimized Testcase (9.64 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97H-tHNQb9fXkiloOL3cctUECLoqpEBtUwrBek91HZ51HTXJ7pzjtb8kVsvyEh8BF1aDGtunO5aL0ouOfkqtjgayXF5xcevUrqru6UWTCXfMnEjvgVkp1ISwY2XN8syE-OFh_ap0XZmph7bjAncYPwnmVGnsA?testcase_id=5806026055221248

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 5 by tebbi@chromium.org, Dec 1 2016

Status: Fixed (was: Assigned)

Sign in to add a comment