CHECK failure: Disposing the isolate that is entered by a thread in isolate.cc |
||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6470105388285952 Fuzzer: libfuzzer_v8_script_parser_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: Disposing the isolate that is entered by a thread in isolate.cc Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=455091:455226 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6470105388285952 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Apr 28 2017
Looks like a left-over pending exception from a previous fuzzer run on the same Isolate.
,
Apr 28 2017
I'll take a look ...
,
May 2 2017
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/c63f1051e3c7fa4c252e7cb3cff8d7530fbeb746 commit c63f1051e3c7fa4c252e7cb3cff8d7530fbeb746 Author: Michael Starzinger <mstarzinger@chromium.org> Date: Tue May 02 10:31:32 2017 [fuzzer] Make parser fuzzer handle pending exceptions. This ensures exceptions thrown during parsing are properly propagated into the surrounding {v8::TryCatch} block. Otherwise running more than one test input in the same Isolate can fail due to pending exceptions. R=jochen@chromium.org BUG= chromium:715037 Change-Id: Iaa5735515dc097d8cb12dcf8672451f3c9503440 Reviewed-on: https://chromium-review.googlesource.com/490047 Commit-Queue: Michael Starzinger <mstarzinger@chromium.org> Reviewed-by: Jochen Eisinger <jochen@chromium.org> Cr-Commit-Position: refs/heads/master@{#45019} [modify] https://crrev.com/c63f1051e3c7fa4c252e7cb3cff8d7530fbeb746/src/isolate.h [modify] https://crrev.com/c63f1051e3c7fa4c252e7cb3cff8d7530fbeb746/test/fuzzer/parser.cc
,
May 2 2017
,
May 3 2017
ClusterFuzz has detected this issue as fixed in range 468615:468644. Detailed report: https://clusterfuzz.com/testcase?key=6470105388285952 Fuzzer: libfuzzer_v8_script_parser_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: Disposing the isolate that is entered by a thread in isolate.cc Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=455091:455226 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=468615:468644 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6470105388285952 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
||||
►
Sign in to add a comment |
||||
Comment 1 by msrchandra@chromium.org
, Apr 25 2017Labels: Test-Predator-Wrong-CLs M-60