Issue metadata
Sign in to add a comment
|
CHECK failure: !field_type->NowStable() || field_type->NowContains(value) || (!FLAG_use_allocat |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6598446651015168 Fuzzer: inferno_js_fuzzer Job Type: linux_asan_d8 Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !field_type->NowStable() || field_type->NowContains(value) || (!FLAG_use_allocat Sanitizer: address (ASAN) Regressed: V8: 44701:44702 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6598446651015168 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 3 2017
Just from the error message I'd be surprised if the mentioned CL is the root cause. I think the CL just changed the gc timing a bit to make this repro work.
,
Jul 5 2017
Probably this is an IC issue, unrelated to either CL mentioned.
,
Jul 14 2017
ClusterFuzz has detected this issue as fixed in range 46621:46622. Detailed report: https://clusterfuzz.com/testcase?key=6598446651015168 Fuzzer: inferno_js_fuzzer Job Type: linux_asan_d8 Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !field_type->NowStable() || field_type->NowContains(value) || (!FLAG_use_allocat Sanitizer: address (ASAN) Regressed: V8: 44701:44702 Fixed: V8: 46621:46622 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6598446651015168 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by clemensh@chromium.org
, Jul 3 2017Owner: kozyatinskiy@chromium.org
Status: Assigned (was: Untriaged)