context_register_count_ > 0 in bytecode-array-builder.cc |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5575542436003840 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_ignition_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: context_register_count_ > 0 in bytecode-array-builder.cc Sanitizer: address (ASAN) Regressed: V8: 42666:42667 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94h_LzWLzzC21NNSQ8dxxzN88VxhXENZmKaEXXWOkODpUEgc-AkXIN429yemlJaVYJU93Ms_f61Q3NfO_uNx9_Z24OYjregLLJrpBhfvzMHgrHx1uzOUCEaZ012CrKhMZy6AwzfvAA5pR4ggrO4pPEn3fizupUz_RKQW6RfSQKLk_aZtxZSlpdOldJU1VisP_bbLJvdBgsMbvzAZltK5fju9EyB0uEReI16VaPKR7Al2WnSam8JR_OUoppT3vb0Dg2R3UY5E9-E0mvGukgguQt5U85XCIw3aMU_MKcuPEuNod1wULBkBaqaQMbdSWOLcZRqOGeCd1TnpK7MFs5Y1sjIaBbJyoIHeF-QebhmE_PIxLCsJfc?testcase_id=5575542436003840 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 26 2017
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/647d7b6c33e8cc37e3c189c717eeab8566e6a656 commit 647d7b6c33e8cc37e3c189c717eeab8566e6a656 Author: rmcilroy <rmcilroy@chromium.org> Date: Thu Jan 26 10:27:40 2017 [Compiler] Put background compilation of eager inner functions behind a flag. Disabled until clusterfuzz issues are sorted. BUG= v8:5203 , v8:5215 , chromium:685515 , chromium:685476 Review-Url: https://codereview.chromium.org/2658803002 Cr-Commit-Position: refs/heads/master@{#42686} [modify] https://crrev.com/647d7b6c33e8cc37e3c189c717eeab8566e6a656/src/compiler.cc [modify] https://crrev.com/647d7b6c33e8cc37e3c189c717eeab8566e6a656/src/flag-definitions.h
,
Jan 27 2017
ClusterFuzz has detected this issue as fixed in range 42685:42686. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5575542436003840 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_ignition_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: context_register_count_ > 0 in bytecode-array-builder.cc Sanitizer: address (ASAN) Regressed: V8: 42666:42667 Fixed: V8: 42685:42686 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94h_LzWLzzC21NNSQ8dxxzN88VxhXENZmKaEXXWOkODpUEgc-AkXIN429yemlJaVYJU93Ms_f61Q3NfO_uNx9_Z24OYjregLLJrpBhfvzMHgrHx1uzOUCEaZ012CrKhMZy6AwzfvAA5pR4ggrO4pPEn3fizupUz_RKQW6RfSQKLk_aZtxZSlpdOldJU1VisP_bbLJvdBgsMbvzAZltK5fju9EyB0uEReI16VaPKR7Al2WnSam8JR_OUoppT3vb0Dg2R3UY5E9-E0mvGukgguQt5U85XCIw3aMU_MKcuPEuNod1wULBkBaqaQMbdSWOLcZRqOGeCd1TnpK7MFs5Y1sjIaBbJyoIHeF-QebhmE_PIxLCsJfc?testcase_id=5575542436003840 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 27 2017
Just put behind a flag. Adding label to make sure we don't loose the report.
,
Feb 10 2017
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/96009d28dcf77207dad614a6473eccb117bfb2f2 commit 96009d28dcf77207dad614a6473eccb117bfb2f2 Author: Ross McIlroy <rmcilroy@chromium.org> Date: Fri Feb 10 22:40:24 2017 [Compiler] Avoid stepping a job in EnqueueAndStep if job is already enqueued. If a job was already enqueued, EnqueueAndStep would still step the job one more step. However, since it didn't take the job out of the pending_background_jobs pool, the job could get picked up by a background thread which would try to step it, but it the job is now at a step which can't be run on the background. BUG= v8:5203 , chromium:685515 Change-Id: I2cee2a33625ba455aca49a8037601be9ff8bb73f Reviewed-on: https://chromium-review.googlesource.com/441084 Commit-Queue: Ross McIlroy <rmcilroy@chromium.org> Reviewed-by: Jochen Eisinger <jochen@chromium.org> Cr-Commit-Position: refs/heads/master@{#43121} [modify] https://crrev.com/96009d28dcf77207dad614a6473eccb117bfb2f2/src/compiler-dispatcher/compiler-dispatcher.cc [modify] https://crrev.com/96009d28dcf77207dad614a6473eccb117bfb2f2/src/compiler-dispatcher/compiler-dispatcher.h [modify] https://crrev.com/96009d28dcf77207dad614a6473eccb117bfb2f2/test/unittests/compiler-dispatcher/compiler-dispatcher-unittest.cc
,
Feb 10 2017
,
Sep 18 2017
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label. |
||||
►
Sign in to add a comment |
||||
Comment 1 by mstarzinger@chromium.org
, Jan 26 2017Status: Assigned (was: Untriaged)