!retval.is_null() in asm-js.cc |
||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6162013429694464 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_ignition_v8_arm_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !retval.is_null() in asm-js.cc Regressed: V8: r41371:41372 Minimized Testcase (0.84 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96SroqugwFIYk5PfUmHjaK8CMyt4qlCVYYjXetA9aEaLcm61QBAK0JKiumJ0Xa6fsSAp3UQT1OmFjhxh4C56v1bn4O89uI5nvEU74aT8uXnkt5WBGFlnnXO_mcD9y2U10VJwa9AY2Z4mved74fnoVi1SEFIZg?testcase_id=6162013429694464 Issue manually filed by: ishell See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 10 2017
Fix out for review: https://codereview.chromium.org/2620893002/
,
Jan 11 2017
ClusterFuzz has detected this issue as fixed in range 42190:42191. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6162013429694464 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_ignition_v8_arm_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !retval.is_null() in asm-js.cc Sanitizer: address (ASAN) Regressed: V8: r41371:41372 Fixed: V8: r42190:42191 Minimized Testcase (0.84 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96SroqugwFIYk5PfUmHjaK8CMyt4qlCVYYjXetA9aEaLcm61QBAK0JKiumJ0Xa6fsSAp3UQT1OmFjhxh4C56v1bn4O89uI5nvEU74aT8uXnkt5WBGFlnnXO_mcD9y2U10VJwa9AY2Z4mved74fnoVi1SEFIZg?testcase_id=6162013429694464 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 11 2017
ClusterFuzz testcase 6162013429694464 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by ishell@chromium.org
, Dec 22 2016Owner: bradnelson@chromium.org
Status: Assigned (was: Untriaged)