New issue
Advanced search Search tips

Issue 719378 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: May 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Ill in __RT_impl_Runtime_AbortJS

Project Member Reported by ClusterFuzz, May 8 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5295566635663360

Fuzzer: inferno_js_fuzzer
Job Type: linux_asan_d8
Platform Id: linux

Crash Type: Ill
Crash Address: 0x7fd5ef09a4f8
Crash State:
  __RT_impl_Runtime_AbortJS
  v8::internal::Runtime_AbortJS
  v8::internal::Invoke
  
Sanitizer: address (ASAN)

Regressed: V8: 33377:33378

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5295566635663360


Issue manually filed by: rossberg

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: jarin@chromium.org
Status: Assigned (was: Untriaged)
@jarin, as the reviewer of @yangguo's CL, can you please have a look?
Owner: ----
Status: Untriaged (was: Assigned)
Oops, please disregard, wrong tab. :)
Project Member

Comment 3 by ClusterFuzz, May 8 2017

Detailed report: https://clusterfuzz.com/testcase?key=4872556783075328

Fuzzer: inferno_js_fuzzer
Job Type: linux_asan_d8_v8_arm64_dbg
Platform Id: linux

Crash Type: Ill
Crash Address: 0x7f1667fcc378
Crash State:
  v8::internal::__RT_impl_Runtime_AbortJS
  v8::internal::Runtime_AbortJS
  v8::internal::Simulator::DoRuntimeCall
  
Sanitizer: address (ASAN)

Regressed: V8: 33377:33378

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4872556783075328


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Owner: u...@chromium.org
Status: Assigned (was: Untriaged)
Looks like the latest clang finds new issues. @ulan, can you perhaps have a look, or reassign?
Labels: -Type-Bug-Security -Security_Severity-High Security_Severity-Medium Pri-2 Type-Bug
Failure occurs in calls to internal %AbortJS, which is only accessible to tests and not in production. Lowering security severity.

Comment 6 by aarya@google.com, May 16 2017

Status: WontFix (was: Assigned)
This is a fuzzer bug, we needed for neuter AbortJS call in fuzzed testcases.
Project Member

Comment 7 by ClusterFuzz, Jul 14 2017

Labels: Needs-Feedback
ClusterFuzz testcase 4872556783075328 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
Project Member

Comment 8 by sheriffbot@chromium.org, Aug 23 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment