Issue metadata
Sign in to add a comment
|
CHECK failure: LoadElement of kRepFloat64 (NumberOrHole) cannot be changed to kRepTagged in rep |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6014324345929728 Fuzzer: mbarbella_js_mutation Job Type: windows_asan_d8 Platform Id: windows Crash Type: CHECK failure Crash Address: Crash State: LoadElement of kRepFloat64 (NumberOrHole) cannot be changed to kRepTagged in rep v8::platform::PrintStackTrace v8::internal::compiler::RepresentationChanger::TypeError Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=470799:470804 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6014324345929728 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
May 12 2017
,
May 13 2017
ClusterFuzz has detected this issue as fixed in range 471275:471285. Detailed report: https://clusterfuzz.com/testcase?key=6014324345929728 Fuzzer: mbarbella_js_mutation Job Type: windows_asan_d8 Platform Id: windows Crash Type: CHECK failure Crash Address: Crash State: LoadElement of kRepFloat64 (NumberOrHole) cannot be changed to kRepTagged in rep v8::platform::PrintStackTrace v8::internal::compiler::RepresentationChanger::TypeError Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=470799:470804 Fixed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=471275:471285 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6014324345929728 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by bmeu...@chromium.org
, May 12 2017Status: Assigned (was: Untriaged)