New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 684855 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Feb 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug

Blocked on:
issue 5882



Sign in to add a comment

Timeout in v8_wasm_names_section_fuzzer

Project Member Reported by ClusterFuzz, Jan 24 2017

Issue description

Cc: msrchandra@chromium.org
Labels: Test-Predator-Wrong
Owner: ahaas@chromium.org
Status: Assigned (was: Untriaged)
This issue looks similar to that of Bug ID: 684983.

@ahaas -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.

Comment 2 by ahaas@chromium.org, Jan 25 2017

Cc: ahaas@chromium.org
 Issue 684983  has been merged into this issue.
Project Member

Comment 3 by bugdroid1@chromium.org, Feb 2 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/v8/v8.git/+/864799d3ebbaeb8d1d54192fe97c6dc30ecd3e66

commit 864799d3ebbaeb8d1d54192fe97c6dc30ecd3e66
Author: ahaas <ahaas@chromium.org>
Date: Thu Feb 02 08:38:34 2017

[wasm] Decoding the names section should stop if there is a problem with locals.

First discovery by the names section fuzzer I think. During the decoding
of the names of locals only ok() of the outer decoder was checked, not
the ok() of the actual names section decoder.

R=tizer@chromium.org
BUG= chromium:684855 

Review-Url: https://codereview.chromium.org/2648383007
Cr-Commit-Position: refs/heads/master@{#42880}

[modify] https://crrev.com/864799d3ebbaeb8d1d54192fe97c6dc30ecd3e66/src/wasm/decoder.h
[modify] https://crrev.com/864799d3ebbaeb8d1d54192fe97c6dc30ecd3e66/src/wasm/module-decoder.cc
[modify] https://crrev.com/864799d3ebbaeb8d1d54192fe97c6dc30ecd3e66/test/unittests/wasm/module-decoder-unittest.cc

Comment 4 by ahaas@chromium.org, Feb 2 2017

 Issue 684854  has been merged into this issue.
Cc: clemensh@chromium.org
This is a low-risk change which avoids crashes. Should be merge it back to M57?
Blockedon: 5882
FYI: The original CL introducing the error was already merged back: https://bugs.chromium.org/p/v8/issues/detail?id=5882
Project Member

Comment 8 by ClusterFuzz, Feb 3 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 4654951931576320 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment