V8 correctness failure in configs: x64,ignition:ia32,ignition |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6224859081474048 Fuzzer: foozzie_js_mutation Job Type: foozzie_ignition_x64_ia32 Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:ia32,ignition sources: fb9 Sanitizer: address (ASAN) Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97RDHjLkjSs5a890yigwDYujk-yISvA_In0jmaawAgRAarrx9ESTfHgeNBSpgUTDQyI-d378GB7hDwacd6QcwDUR1gZHr_IC-N-AY2gr1VF_ILdDSWdJvsxI9PGs58bWF5wjW1dYi46uA0ZNeWHftmj_ulZs_goxAozPop9uVk0j5uqUVUXwo4GEb7KE3RqfHruT3v0jk_QNwFxLS5ckhZyg-t-aTpt1e6F2LOYq7lFIOrvFN2_UbewWNoPE-kc3wDsdUiG1YELVVwhh8dgXzzOvHSc9FYVg6ULCF1U-yAbFBX5eYxaXQpBVXmI-O3CSsyHT1mnfDSW2kyJZrKJnq18Am_aBqEGs9TX24G2nQPia4MB8hQ?testcase_id=6224859081474048 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Feb 3 2017
The exponentiation operation is actually constant folded by the parser. Most likely this is pure dupe of issue v8:5848.
,
Feb 7 2017
Issue 689362 has been merged into this issue.
,
Feb 9 2017
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/d128338d231713d80ded009a1d90264870dbbeec commit d128338d231713d80ded009a1d90264870dbbeec Author: Michael Achenbach <machenbach@chromium.org> Date: Thu Feb 09 08:33:16 2017 [foozzie] Suppress crbug.com/688159 BUG= chromium:688159 NOTRY=true TBR=bmeurer@chromium.org,mstarzinger@chromium.org Change-Id: I9b5c0c531af31534a0dd33e078a148b822834448 Reviewed-on: https://chromium-review.googlesource.com/439184 Reviewed-by: Michael Achenbach <machenbach@chromium.org> Commit-Queue: Michael Achenbach <machenbach@chromium.org> Cr-Commit-Position: refs/heads/master@{#43053} [modify] https://crrev.com/d128338d231713d80ded009a1d90264870dbbeec/tools/foozzie/v8_suppressions.py
,
Feb 10 2017
ClusterFuzz has detected this issue as fixed in range 43052:43053. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6224859081474048 Fuzzer: foozzie_js_mutation Job Type: foozzie_ignition_x64_ia32 Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:ia32,ignition sources: fb9 Sanitizer: address (ASAN) Fixed: V8: 43052:43053 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97RDHjLkjSs5a890yigwDYujk-yISvA_In0jmaawAgRAarrx9ESTfHgeNBSpgUTDQyI-d378GB7hDwacd6QcwDUR1gZHr_IC-N-AY2gr1VF_ILdDSWdJvsxI9PGs58bWF5wjW1dYi46uA0ZNeWHftmj_ulZs_goxAozPop9uVk0j5uqUVUXwo4GEb7KE3RqfHruT3v0jk_QNwFxLS5ckhZyg-t-aTpt1e6F2LOYq7lFIOrvFN2_UbewWNoPE-kc3wDsdUiG1YELVVwhh8dgXzzOvHSc9FYVg6ULCF1U-yAbFBX5eYxaXQpBVXmI-O3CSsyHT1mnfDSW2kyJZrKJnq18Am_aBqEGs9TX24G2nQPia4MB8hQ?testcase_id=6224859081474048 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Feb 10 2017
ClusterFuzz testcase 6224859081474048 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by machenb...@chromium.org
, Feb 3 2017Labels: -Pri-1 Pri-2
Status: Available (was: Untriaged)