New issue
Advanced search Search tips

Issue 722348 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Closed: May 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug


Participants' hotlists:
Hotlist-AsmJsParser


Sign in to add a comment

V8 correctness failure in configs: x64,ignition:x64,ignition_asm

Project Member Reported by ClusterFuzz, May 15 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4887994405486592

Fuzzer: foozzie_js_mutation
Job Type: v8_foozzie
Platform Id: linux

Crash Type: V8 correctness failure
Crash Address: 
Crash State:
  configs: x64,ignition:x64,ignition_asm
  sources: 8e4
  
Sanitizer: address (ASAN)

Regressed: V8: 44941:44942

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4887994405486592


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: mstarzinger@chromium.org
Status: Assigned (was: Untriaged)
Project Member

Comment 2 by ClusterFuzz, May 16 2017

ClusterFuzz has detected this issue as fixed in range 45316:45317.

Detailed report: https://clusterfuzz.com/testcase?key=4887994405486592

Fuzzer: foozzie_js_mutation
Job Type: v8_foozzie
Platform Id: linux

Crash Type: V8 correctness failure
Crash Address: 
Crash State:
  configs: x64,ignition:x64,ignition_asm
  sources: 8e4
  
Sanitizer: address (ASAN)

Regressed: V8: 44941:44942
Fixed: V8: 45316:45317

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4887994405486592


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, May 16 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 4887994405486592 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Labels: ClusterFuzz-Wrong
Status: Assigned (was: Verified)
Pretty closely related to  issue 719384 . Thanks!
Project Member

Comment 6 by bugdroid1@chromium.org, May 22 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/v8/v8.git/+/d813f46e0b62b006d1b4a832ee2587ca9808831d

commit d813f46e0b62b006d1b4a832ee2587ca9808831d
Author: Michael Starzinger <mstarzinger@chromium.org>
Date: Mon May 22 11:41:07 2017

[asm.js] Properly handle unused function imports.

This makes sure that function imports without a single call site within
the asm.js module are still preserved in the WebAssembly module, hence
preserving intended JavaScript semantics during module instantiation.

R=clemensh@chromium.org
TEST=mjsunit/regress/regress-crbug-722348
BUG= chromium:722348 

Change-Id: I624d0e52b32b864c1e3002187a99a0a63834a4b0
Reviewed-on: https://chromium-review.googlesource.com/509450
Reviewed-by: Clemens Hammacher <clemensh@chromium.org>
Commit-Queue: Michael Starzinger <mstarzinger@chromium.org>
Cr-Commit-Position: refs/heads/master@{#45452}
[modify] https://crrev.com/d813f46e0b62b006d1b4a832ee2587ca9808831d/src/asmjs/asm-parser.cc
[add] https://crrev.com/d813f46e0b62b006d1b4a832ee2587ca9808831d/test/mjsunit/regress/regress-crbug-722348.js

Status: Fixed (was: Assigned)
Project Member

Comment 8 by ClusterFuzz, May 23 2017

ClusterFuzz has detected this issue as fixed in range 45451:45452.

Detailed report: https://clusterfuzz.com/testcase?key=4887994405486592

Fuzzer: foozzie_js_mutation
Job Type: v8_foozzie
Platform Id: linux

Crash Type: V8 correctness failure
Crash Address: 
Crash State:
  configs: x64,ignition:x64,ignition_asm
  sources: 8e4
  
Sanitizer: address (ASAN)

Regressed: V8: 44941:44942
Fixed: V8: 45451:45452

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4887994405486592


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Labels: -ClusterFuzz-Wrong
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label.

Sign in to add a comment