Out-of-memory in v8_wasm_fuzzer |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6177002509041664 Fuzzer: libfuzzer_v8_wasm_fuzzer Job Type: libfuzzer_chrome_msan Platform Id: linux Crash Type: Out-of-memory (exceeds 2048 MB) Crash Address: Crash State: v8_wasm_fuzzer Sanitizer: memory (MSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=442579:442625 Minimized Testcase (0.11 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97Rhoewo9HzePGqZESUA_ZkmjGAgvMKZTcbjO1O5WSNZ957rzgNMEI3pWKy_rOZekLU442JO6MrtyAhuqlto7GFRstVgpeOo_fjayBVboT5Lxp6aq5zSF8YPM616BFawNyHD2BdpRoODgEdZ1x3vEpiViJO5cfLzoywxzjEs6UoTRtkbLYwWUUN9eFRkJOisNmzsmPUbrrnBdVzSfuOiiaVoyO4Z55nbcOH_-4OMdz89qA_yynOqsBm8yPwTrmmesDaZ4b8UzfHKTgaUGeXUozjc87KbCpiffv15bby2Sn3aL8UyMbfu47XpkjOnU7J2HB0lRMPuxngtapUdOPkt8EcQ7ZmVE1HsYOcJ8mgjsAEJejhohvznV8EHzHIIT1HWgpo-Jmle-PobYWoRFNrIzEnEQxOdA?testcase_id=6177002509041664 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Jan 16 2017
,
Jan 17 2017
The problem here is that the wasm module that is generated by the fuzzer correctly allocates more memory than CF provides on its machines. In this issue it allocates an indirect function table of initial size = 2095876. Ideally we should define lower limits for the table size (or memory size) for the fuzzer, but I am not sure yet how to do this the best way. In any case, this should be quite low priority because it is actually correct behavior the fuzzer cannot deal with.
,
Jan 25 2017
ClusterFuzz has detected this issue as fixed in range 445714:445793. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6177002509041664 Fuzzer: libfuzzer_v8_wasm_fuzzer Job Type: libfuzzer_chrome_msan Platform Id: linux Crash Type: Out-of-memory (exceeds 2048 MB) Crash Address: Crash State: v8_wasm_fuzzer Sanitizer: memory (MSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=442579:442625 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=445714:445793 Minimized Testcase (0.11 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97Rhoewo9HzePGqZESUA_ZkmjGAgvMKZTcbjO1O5WSNZ957rzgNMEI3pWKy_rOZekLU442JO6MrtyAhuqlto7GFRstVgpeOo_fjayBVboT5Lxp6aq5zSF8YPM616BFawNyHD2BdpRoODgEdZ1x3vEpiViJO5cfLzoywxzjEs6UoTRtkbLYwWUUN9eFRkJOisNmzsmPUbrrnBdVzSfuOiiaVoyO4Z55nbcOH_-4OMdz89qA_yynOqsBm8yPwTrmmesDaZ4b8UzfHKTgaUGeXUozjc87KbCpiffv15bby2Sn3aL8UyMbfu47XpkjOnU7J2HB0lRMPuxngtapUdOPkt8EcQ7ZmVE1HsYOcJ8mgjsAEJejhohvznV8EHzHIIT1HWgpo-Jmle-PobYWoRFNrIzEnEQxOdA?testcase_id=6177002509041664 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 25 2017
ClusterFuzz testcase 6177002509041664 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by mummare...@chromium.org
, Jan 11 2017