var->is_function() in asm-wasm-builder.cc |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5687337351905280 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_ignition_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: type != AsmType::None() in asm-wasm-builder.cc Regressed: V8: r41514:41515 Minimized Testcase (5.19 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97LMAnCjfC-s9pqEG0587Jg7Jyy4ts2sGKtwpA57oat5_o1lYmytzJAUy9ZVXJAZ8bGbXenEP8mj7xUTh7BxzI7BK6JojzycQn3kJmnjX6zE_tsGt0jyhSzCAaOnQRcOwwaf2695WW3JDb7RtyMX2Mc2LI9Uw?testcase_id=5687337351905280 Issue manually filed by: ishell See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 12 2016
CF points to 3e8a67e5406be46e971908d69af93bf92b6ff980
,
Dec 12 2016
Fix for first issue: https://codereview.chromium.org/2568773002/
,
Dec 12 2016
Fix second issue: https://codereview.chromium.org/2565343002
,
Dec 13 2016
ClusterFuzz has detected this issue as fixed in range 41642:41643. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5687337351905280 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_ignition_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: type != AsmType::None() in asm-wasm-builder.cc Regressed: V8: r41514:41515 Fixed: V8: r41642:41643 Minimized Testcase (5.19 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97LMAnCjfC-s9pqEG0587Jg7Jyy4ts2sGKtwpA57oat5_o1lYmytzJAUy9ZVXJAZ8bGbXenEP8mj7xUTh7BxzI7BK6JojzycQn3kJmnjX6zE_tsGt0jyhSzCAaOnQRcOwwaf2695WW3JDb7RtyMX2Mc2LI9Uw?testcase_id=5687337351905280 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Dec 13 2016
ClusterFuzz has detected this issue as fixed in range 41637:41638. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5625762385494016 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_ignition_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: var->is_function() in asm-wasm-builder.cc Regressed: V8: r41514:41515 Fixed: V8: r41637:41638 Minimized Testcase (8.75 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94_uN774cuSlAoDp1CfA8ibSXko3XIERgCjh_t5ACMcE3WDqA7b3G1jQOKehgbcwhGS01IQF-Jtu2CunChAOTwHfs_io3vRJCdhJiMCSEYHkYbsHTOOYuYBXMidPtp5gKAr4eofTlcgoc53GQtUiBFvAwuBDw?testcase_id=5625762385494016 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Dec 13 2016
ClusterFuzz testcase 5625762385494016 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by ClusterFuzz
, Dec 12 2016