Detailed report: https://clusterfuzz.com/testcase?key=6347933978198016 Fuzzer: mbarbella_js_mutation Job Type: windows_asan_d8 Platform Id: windows Crash Type: UNKNOWN READ Crash Address: 0x00000010 Crash State: v8::internal::compiler::Node::New v8::internal::compiler::Graph::NewNode v8::internal::compiler::GraphAssembler::DeoptimizeUnless Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=460544:464119 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94GaFCxAMK8Mzd_rZecLG0ZsZ2hErSPaE4Z5KC3cviDoISO4lNSN7h9TCnJL2Ip5XT_OP_RcDLJkHMgd4TAhDLwyI3jYRcWz3-GzeMGHBa1xANkzmHA0yPUNzHyda0jpKC6UyaOTNqdCsdbPB8f-Nfxcl90gVZzy-gZrsh351dz3_5mtWuU5Iux5BznI_y3XfgrW_XGGWHokB9ZmD-Y-1g3kduUiMS9YiiWLNaRa5Mb5wVsQPppMsuCbs73IvqPaXNWxu7iYk_rYiznQPZnVbnC6UL1levQdkrAUmWgN8h8bxyol1Kh5PEepfG7VXrFWl7CCzkxxkW2CrMOYYi0_-K3g-fBATeEc4q2beaBW410kwQh2M8?testcase_id=6347933978198016 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Looks very much like v8:6248 which I already fixed.
ClusterFuzz has detected this issue as fixed in range 464871:464873. Detailed report: https://clusterfuzz.com/testcase?key=6347933978198016 Fuzzer: mbarbella_js_mutation Job Type: windows_asan_d8 Platform Id: windows Crash Type: UNKNOWN READ Crash Address: 0x00000010 Crash State: v8::internal::compiler::Node::New v8::internal::compiler::Graph::NewNode v8::internal::compiler::GraphAssembler::DeoptimizeUnless Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=460544:464119 Fixed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=464871:464873 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94GaFCxAMK8Mzd_rZecLG0ZsZ2hErSPaE4Z5KC3cviDoISO4lNSN7h9TCnJL2Ip5XT_OP_RcDLJkHMgd4TAhDLwyI3jYRcWz3-GzeMGHBa1xANkzmHA0yPUNzHyda0jpKC6UyaOTNqdCsdbPB8f-Nfxcl90gVZzy-gZrsh351dz3_5mtWuU5Iux5BznI_y3XfgrW_XGGWHokB9ZmD-Y-1g3kduUiMS9YiiWLNaRa5Mb5wVsQPppMsuCbs73IvqPaXNWxu7iYk_rYiznQPZnVbnC6UL1levQdkrAUmWgN8h8bxyol1Kh5PEepfG7VXrFWl7CCzkxxkW2CrMOYYi0_-K3g-fBATeEc4q2beaBW410kwQh2M8?testcase_id=6347933978198016 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
ClusterFuzz testcase 6347933978198016 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Comment 1 by mstarzinger@chromium.org
, Apr 19 2017Components: -Blink>JavaScript Blink>JavaScript>Compiler
Owner: mstarzinger@chromium.org
Status: Assigned (was: Untriaged)