Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5309290572414976 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_v8_arm64_dbg Platform Id: linux Crash Type: Unreachable code Crash Address: Crash State: objects-inl.h Regressed: V8: r41690:41691 Minimized Testcase (0.62 Kb): https://cluster-fuzz.appspot.com/download/AMIfv951lUJnD-Omf01o0qR18udNC8eVYM-XtXan0rjRelWrb52OqBVZJBNdIxaXFhJug_aidJ6EZX50xQHVE1lNgyz4-Zs_mDCkIdKP63Wb-F0E_cBnQ_cbRPyPFZqj3u2Zv2J_NI2H4wRc96cDepk7_Y06yxYijw?testcase_id=5309290572414976 Issue manually filed by: ishell See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
CF points to 576abe14c673eefc4aaf3aaba4b4b670b1d87a12.
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/cbd3b3d0fe2439f8835c81658a6d685a0ce95480 commit cbd3b3d0fe2439f8835c81658a6d685a0ce95480 Author: titzer <titzer@chromium.org> Date: Tue Dec 20 10:38:17 2016 Implement header size calculation for array iterators. R=bmeurer@chromium.org BUG= chromium:674232 Review-Url: https://codereview.chromium.org/2592633002 Cr-Commit-Position: refs/heads/master@{#41849} [modify] https://crrev.com/cbd3b3d0fe2439f8835c81658a6d685a0ce95480/src/objects-inl.h [add] https://crrev.com/cbd3b3d0fe2439f8835c81658a6d685a0ce95480/test/mjsunit/regress/regress-674232.js
ClusterFuzz has detected this issue as fixed in range 41848:41849. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5309290572414976 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_v8_arm64_dbg Platform Id: linux Crash Type: Unreachable code Crash Address: Crash State: objects-inl.h Regressed: V8: r41690:41691 Fixed: V8: r41848:41849 Minimized Testcase (0.62 Kb): https://cluster-fuzz.appspot.com/download/AMIfv951lUJnD-Omf01o0qR18udNC8eVYM-XtXan0rjRelWrb52OqBVZJBNdIxaXFhJug_aidJ6EZX50xQHVE1lNgyz4-Zs_mDCkIdKP63Wb-F0E_cBnQ_cbRPyPFZqj3u2Zv2J_NI2H4wRc96cDepk7_Y06yxYijw?testcase_id=5309290572414976 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Comment 1 by ishell@chromium.org
, Dec 14 2016Owner: titzer@chromium.org
Status: Assigned (was: Untriaged)