New issue
Advanced search Search tips

Issue 686125 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 685680
Owner: ----
Closed: Jan 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Encountered unaccounted use by #161 (Call) in escape-analysis.cc

Project Member Reported by ClusterFuzz, Jan 27 2017

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5447130060947456

Fuzzer: inferno_webbot
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  Encountered unaccounted use by #161 (Call) in escape-analysis.cc
  v8::internal::compiler::EscapeStatusAnalysis::CheckUsesForEscape
  v8::internal::compiler::EscapeStatusAnalysis::ProcessFinishRegion
  v8::internal::compiler::EscapeStatusAnalysis::Process
  
Sanitizer: address (ASAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=446318:446606

Minimized Testcase (0.05 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97LvS6qgpy2Gzb7PZvmfx-C2AESI6MPh2kzGvaKOj8uGIxNlhE3fdyXrcvhiH84rMzk3bm60sr3U65DnJYYmVKp0MvhPnvKfVBzaOhogFdYHayLXd57rpc-RiqRbgFQEDgQLZlOZSlFVzutjxL8CsamoAoV9Ad1swx0ptIPyEThCljMfcOmiwEQW73oc5wLSNPYMDeeQS6d-7gfIv_oXfH6852RyNvzQ26lge4bVByae1dfWTs3s1v8BUKKJRCYyC3horhk45NLQGyePkcmJ8D8SaSk9J_ziAevVe2Sx_hEzafpO9EKfOXhas0fNLfbKeTqPS4Vl3BaiNAfau3QbeUqkN_tmhhc4tlm95yGoBigl7GPjhg?testcase_id=5447130060947456
<script>
window.location = "http://ace.jp";</script>


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink>JavaScript
Mergedinto: 685680
Status: Duplicate (was: Untriaged)
Project Member

Comment 2 by ClusterFuzz, Jan 28 2017

ClusterFuzz has detected this issue as fixed in range 446650:446719.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5447130060947456

Fuzzer: inferno_webbot
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  Encountered unaccounted use by #161 (Call) in escape-analysis.cc
  v8::internal::compiler::EscapeStatusAnalysis::CheckUsesForEscape
  v8::internal::compiler::EscapeStatusAnalysis::ProcessFinishRegion
  v8::internal::compiler::EscapeStatusAnalysis::Process
  
Sanitizer: address (ASAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=446318:446606
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=446650:446719

Minimized Testcase (0.05 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97LvS6qgpy2Gzb7PZvmfx-C2AESI6MPh2kzGvaKOj8uGIxNlhE3fdyXrcvhiH84rMzk3bm60sr3U65DnJYYmVKp0MvhPnvKfVBzaOhogFdYHayLXd57rpc-RiqRbgFQEDgQLZlOZSlFVzutjxL8CsamoAoV9Ad1swx0ptIPyEThCljMfcOmiwEQW73oc5wLSNPYMDeeQS6d-7gfIv_oXfH6852RyNvzQ26lge4bVByae1dfWTs3s1v8BUKKJRCYyC3horhk45NLQGyePkcmJ8D8SaSk9J_ziAevVe2Sx_hEzafpO9EKfOXhas0fNLfbKeTqPS4Vl3BaiNAfau3QbeUqkN_tmhhc4tlm95yGoBigl7GPjhg?testcase_id=5447130060947456
<script>
window.location = "http://ace.jp";</script>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment