V8 correctness failure in configs: x64,ignition:x64,ignition_turbo_opt (Exception source positions don't agree) |
|||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4994045553410048 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,ignition_turbo_opt sources: c6e Sanitizer: address (ASAN) Regressed: V8: 45924:45925 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4994045553410048 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jun 19 2017
,
Jun 19 2017
This will be fixed with the asm.js validator as it involves invalid asm.js code. Hence most likely a WontFix in the AstGraphBuilder. I'll hold this for now.
,
Jun 20 2017
,
Jun 26 2017
Issue 736663 has been merged into this issue.
,
Jun 29 2017
ClusterFuzz has detected this issue as fixed in range 46282:46284. Detailed report: https://clusterfuzz.com/testcase?key=4994045553410048 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,ignition_turbo_opt sources: c6e Sanitizer: address (ASAN) Regressed: V8: 45924:45925 Fixed: V8: 46282:46284 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4994045553410048 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jun 29 2017
Is this really fixed by comment 6? Or does that maybe fix a particular instance only?
,
Jun 29 2017
ClusterFuzz testcase 4994045553410048 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jun 29 2017
Please verify this manually as it looks more like an accidental fix.
,
Jun 29 2017
Re #9: Yes, this is just an "accidental fix", my guess is due to changes of property enumeration order. Status of this issue is unchanged since comment #3, this is a WontFix in the AstGraphBuilder and will be fixed by shipping the asm.js validator.
,
Jul 12 2017
,
Jul 12 2017
Issue 740545 has been merged into this issue.
,
Aug 11 2017
,
Sep 18 2017
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label. |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by jarin@chromium.org
, Jun 15 2017Status: Assigned (was: Untriaged)