Crash in v8::internal::MemoryChunk::heap |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5938603772608512 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000038 Crash State: v8::internal::MemoryChunk::heap v8::internal::Map::IsBooleanMap v8::internal::compiler::CanInlinePropertyAccess Sanitizer: address (ASAN) Minimized Testcase (0.17 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv94Er2saJD37GRzeqRvjp4luL1lwsgO8Z6Y60iMx-Ch5j32XARm70YSMLrluMNXNk-9gmjzoqqUUNqweY4gO6GzX6XSN_lG01Vr73SOvdFopNMaaLSiK7s4Sz_3aRAJdqL0hh6uRlgbtW0GgBT5ZkJptEzP_ER_pzIQWhOkWndNKl5El2-XnnlBqTViWWclOzPkJV5_vLEM-35sveKohsbSEtVpc-Y_ah5GqK-lUEUIHKAMsS9gLcDnPGeJxLNZDm2RWNpvq7vyLE0VBu7vb957rHexnLZwMSzrUHUHBBV-tLtG6YHTAp9bhHbDdNooFvPC7_w8gVJSux5zXkJJir6Kdrlmmk08dCWWVgg4_B42Qsoh8I5ptaewZJpO9PXODlKBK28xIQUMB2AAPLhC2soDLs9PKng?testcase_id=5938603772608512 function __f_8(one) { class __v_6 { static foo() { return one + 6; } } } for (var __v_13 = 0; __v_13 < 5; ++__v_13) __f_8(); %OptimizeFunctionOnNextCall(__f_8); gc(); __f_8(); Issue manually filed by: ishell See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 11 2017
CF points to 088df4e13805b5a41bca3ed19030ff7c0c6f2df0.
,
Jan 11 2017
Issue 680118 has been merged into this issue.
,
Jan 13 2017
ClusterFuzz has detected this issue as fixed in range 42263:42264. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5938603772608512 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000038 Crash State: v8::internal::MemoryChunk::heap v8::internal::Map::IsBooleanMap v8::internal::compiler::CanInlinePropertyAccess Sanitizer: address (ASAN) Regressed: V8: r42209:42210 Fixed: V8: r42263:42264 Minimized Testcase (0.17 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv94Er2saJD37GRzeqRvjp4luL1lwsgO8Z6Y60iMx-Ch5j32XARm70YSMLrluMNXNk-9gmjzoqqUUNqweY4gO6GzX6XSN_lG01Vr73SOvdFopNMaaLSiK7s4Sz_3aRAJdqL0hh6uRlgbtW0GgBT5ZkJptEzP_ER_pzIQWhOkWndNKl5El2-XnnlBqTViWWclOzPkJV5_vLEM-35sveKohsbSEtVpc-Y_ah5GqK-lUEUIHKAMsS9gLcDnPGeJxLNZDm2RWNpvq7vyLE0VBu7vb957rHexnLZwMSzrUHUHBBV-tLtG6YHTAp9bhHbDdNooFvPC7_w8gVJSux5zXkJJir6Kdrlmmk08dCWWVgg4_B42Qsoh8I5ptaewZJpO9PXODlKBK28xIQUMB2AAPLhC2soDLs9PKng?testcase_id=5938603772608512 function __f_8(one) { class __v_6 { static foo() { return one + 6; } } } for (var __v_13 = 0; __v_13 < 5; ++__v_13) __f_8(); %OptimizeFunctionOnNextCall(__f_8); gc(); __f_8(); See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 13 2017
ClusterFuzz testcase 5938603772608512 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by ClusterFuzz
, Jan 11 2017