Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4684039362707456 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition_turbo:ia32,ignition_turbo sources: f56 Sanitizer: address (ASAN) Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94Flwa9INcngsdJGx1TljmmalBEw5UZuJtY6deS8EzQBVxAFP2vQi3nNq2VXcWh7zuG6GMifc0-p3QY_IJhfOUz9h78ZdNuw-vQqLlbrNA4xTaCSlw87k-Th579U4GSzwwj0UHkM9kBpqCa0GCKNsB3uPfRs-lqFqLEAiG0LYei3L4FEdwoYSPzfpnVLaOMD2RS4Zteq-lcsVB6ZvX4a9qX46F1zaAx2Iww1bpspbwRszXbMir2anRTCBki-i7P4agNjPPY1hJKr783cabYy_IGHd3o9GoR4vX8qFeSlKgi2OcITLsfH8YzCwXXb-Wlsh8bQ7vj_tzpvytE8efXP_rDuyzKGT7k98HIr8PwDsivqPq3z5MbRRon1lsVMaVfqXauGVfPLDsEW7jJDoHfftVmgGTURg?testcase_id=4684039362707456 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
@Yang,Jaro: How complicated would it be to crash on more stack overflow types (behind the --abort_on_stack_overflow flag), like this one?
Issue 693891 has been merged into this issue.
Issue 686488 has been merged into this issue.
Issue 695785 has been merged into this issue.
I'll try with a better suppression in the original bug for this.
ClusterFuzz has detected this issue as fixed in range 43435:43436. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4684039362707456 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition_turbo:ia32,ignition_turbo sources: f56 Sanitizer: address (ASAN) Fixed: V8: 43435:43436 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94Flwa9INcngsdJGx1TljmmalBEw5UZuJtY6deS8EzQBVxAFP2vQi3nNq2VXcWh7zuG6GMifc0-p3QY_IJhfOUz9h78ZdNuw-vQqLlbrNA4xTaCSlw87k-Th579U4GSzwwj0UHkM9kBpqCa0GCKNsB3uPfRs-lqFqLEAiG0LYei3L4FEdwoYSPzfpnVLaOMD2RS4Zteq-lcsVB6ZvX4a9qX46F1zaAx2Iww1bpspbwRszXbMir2anRTCBki-i7P4agNjPPY1hJKr783cabYy_IGHd3o9GoR4vX8qFeSlKgi2OcITLsfH8YzCwXXb-Wlsh8bQ7vj_tzpvytE8efXP_rDuyzKGT7k98HIr8PwDsivqPq3z5MbRRon1lsVMaVfqXauGVfPLDsEW7jJDoHfftVmgGTURg?testcase_id=4684039362707456 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Comment 1 by machenb...@chromium.org
, Feb 10 2017Status: Available (was: Untriaged)