V8 correctness failure in configs: x64,fullcode:x64,ignition_staging |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5254663852261376 Fuzzer: foozzie_js_mutation Job Type: foozzie_ignition_staging Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,fullcode:x64,ignition_staging sources: a2f Sanitizer: address (ASAN) Minimized Testcase (0.52 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94LZ9SQSbq_0zEw52sUbyQ8hQIW5RW2PiEdpYlqh0F11JFqz0NsR6pHg4iDMMBpX_o2YQZSOK49r_3jLDv1NTwDv-5oA8-bPKpoAemR7x2aCW5gH2KyL_WtmeU6ORtvOdusp_qzhC7MceOuLuROiJJzAEc0gVDMB7_XFN8FiSSnTJQY6Qu7qEuwjk2gBMmLUFCDUkzjlUqLNaltaLnPKmQO-qOQ0oycYt_PE3z7B9Iqp_pmRynXS9V0FtK6CoSnOe2xheyDEPrWmoLbU6-vvbYuHJbRFHMSNLb3wMUu9Iw_s6jIOsso8zWnjnsagy6Mfz5cZ8s-3b46arH2-cGdqN9HQm3X5meh5RC7dvXkJBmmghHpmw8?testcase_id=5254663852261376 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 20 2017
As discussed, moving to machenbach@ for further triage.
,
Jan 24 2017
,
Jan 24 2017
Could be a dupe of issue 683581 , that one also leaks "optimized_out" values. I'll verify once the fix for that is in.
,
Jan 25 2017
Yep, same underlying root cause as issue 683581 , also fixed by efc8cb16d783c923c690be93cd55ae37f947edca.
,
Jan 26 2017
ClusterFuzz has detected this issue as fixed in range 42647:42648. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5254663852261376 Fuzzer: foozzie_js_mutation Job Type: foozzie_ignition_staging Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,fullcode:x64,ignition_staging sources: a2f Sanitizer: address (ASAN) Fixed: V8: 42647:42648 Minimized Testcase (0.52 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94LZ9SQSbq_0zEw52sUbyQ8hQIW5RW2PiEdpYlqh0F11JFqz0NsR6pHg4iDMMBpX_o2YQZSOK49r_3jLDv1NTwDv-5oA8-bPKpoAemR7x2aCW5gH2KyL_WtmeU6ORtvOdusp_qzhC7MceOuLuROiJJzAEc0gVDMB7_XFN8FiSSnTJQY6Qu7qEuwjk2gBMmLUFCDUkzjlUqLNaltaLnPKmQO-qOQ0oycYt_PE3z7B9Iqp_pmRynXS9V0FtK6CoSnOe2xheyDEPrWmoLbU6-vvbYuHJbRFHMSNLb3wMUu9Iw_s6jIOsso8zWnjnsagy6Mfz5cZ8s-3b46arH2-cGdqN9HQm3X5meh5RC7dvXkJBmmghHpmw8?testcase_id=5254663852261376 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
||||
►
Sign in to add a comment |
||||
Comment 1 by machenb...@chromium.org
, Jan 17 2017Labels: v8-foozzie-failure
// Another stack trace difference. Do we care? Simple repro: function foo() { try {; } catch(e) { } bar(42); } %OptimizeFunctionOnNextCall(foo); foo(); function bar(x, a) {a[x]} // Output difference: - ./fuzz-00497.js:7: TypeError: Cannot read property '42' of undefined + ./fuzz-00497.js:7: TypeError: Cannot read property 'optimized_out' of undefined