Unreachable code in ast-value-factory.h |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4528340829732864 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_ignition_dbg Platform Id: linux Crash Type: Unreachable code Crash Address: Crash State: ast-value-factory.h Regressed: V8: r41514:41515 Minimized Testcase (6.78 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94C2OZfIGcRx8-xNEIpWkxQN39PdGGWOyPwWTgW6pSccKllbk8RheLotJbq0bu3R6s4lZJnu9ouMNxyfufwoVw83rVKPZY2Ea5FW37TuOX1kpaPqPKLV215ZCFM83K8QX4oVMSwoM3Ara43GRn9vOKQ6wg3qw?testcase_id=4528340829732864 Issue manually filed by: titzer See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 8 2016
Repro:
function Module() {
"use asm";
function ror(x) {
x = x | true;
}
return { ror: ror };
}
Module();
,
Dec 8 2016
Fix out for review: https://codereview.chromium.org/2555323003/
,
Dec 9 2016
ClusterFuzz has detected this issue as fixed in range 41594:41595. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4528340829732864 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_ignition_dbg Platform Id: linux Crash Type: Unreachable code Crash Address: Crash State: ast-value-factory.h Regressed: V8: r41514:41515 Fixed: V8: r41594:41595 Minimized Testcase (6.78 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94C2OZfIGcRx8-xNEIpWkxQN39PdGGWOyPwWTgW6pSccKllbk8RheLotJbq0bu3R6s4lZJnu9ouMNxyfufwoVw83rVKPZY2Ea5FW37TuOX1kpaPqPKLV215ZCFM83K8QX4oVMSwoM3Ara43GRn9vOKQ6wg3qw?testcase_id=4528340829732864 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Dec 9 2016
ClusterFuzz testcase 4528340829732864 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by titzer@chromium.org
, Dec 7 2016Status: Assigned (was: Untriaged)