New issue
Advanced search Search tips

Issue 689338 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in v8::Utils::ReportOOMFailure

Project Member Reported by ClusterFuzz, Feb 7 2017

Issue description

Cc: nyerramilli@chromium.org
Components: Blink>JavaScript
Status: WontFix (was: Untriaged)
OOM, closing.
Project Member

Comment 3 by ClusterFuzz, Mar 8 2017

ClusterFuzz has detected this issue as fixed in range 455091:455226.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6342532998103040

Fuzzer: libfuzzer_v8_regexp_parser_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x7fe9dd384228
Crash State:
  v8::Utils::ReportOOMFailure
  v8::internal::V8::FatalProcessOutOfMemory
  v8::internal::Assembler::GrowBuffer
  
Sanitizer: address (ASAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=415616:415651
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=455091:455226

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96hCdrkEQh2Ky5fRkcmttXkKJ_hiY7RB7V77goLFe3txdScq8uZSyZnrG5sOr5sZzcU4M_iBRetOE2VnOqWYb5lvJRsYfGZuuOkC9lZ_qRv9cLYJlS0i9FEZh8ylfFfJPZuW3AEpfDpd8to62W-LcBJ_zK3l4vD6hGVXdjW-QEiPnfyCV1yaTY7w0lHucBOSDWKcNVhQ3XGq-zJlBEkk052v3iuhvV1imjPb14lk4Paan3MpfwqvQDc7UiMcBGe3nu4ktF-Ivs5y8XbqYEdblsiMUmr721cGPX_UTNKQ6KkWC4prbA_dJDjNcsavZcMuRDF0lA2DGOiq6uuxAWfZ8CnrsanjThXVHCTCPkKrw-xWBmMpGSQG3wq044iRv39qQyraXhjY6BWdKGi9yQYmWaZuLHWRw?testcase_id=6342532998103040


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment