New issue
Advanced search Search tips

Issue 752493 link

Starred by 2 users

Issue metadata

Status: Verified
Owner:
Closed: Aug 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

CHECK failure: IsMarked(object) in mark-compact.cc

Project Member Reported by ClusterFuzz, Aug 4 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5977328160342016

Fuzzer: inferno_layout_test_unmodified
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: CHECK failure
Crash Address: 
Crash State:
  IsMarked(object) in mark-compact.cc
  gin::PrintStackTrace
  v8::internal::MarkingVerifier::VerifyMarkingOnPage
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=458024:458029

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5977328160342016


Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Components: Blink>JavaScript
Cc: clemensh@chromium.org jbroman@chromium.org
The V8 range in question is https://chromium.googlesource.com/v8/v8/+/4acdb5eec2c79331c47081c23f7d51d3244a2bf0
Owner: jbroman@chromium.org
Status: Assigned (was: Untriaged)
Cc: -jbroman@chromium.org
Owner: hablich@chromium.org
After poking at this for awhile, I realized I'm not actually in the regression range here. The regression range (per Clusterfuzz) is:

https://chromium.googlesource.com/chromium/src/+log/4342d3eacba11f513071dd4bb06b182b4f1245f3..4844f72ece1a4a870e571e8e53746bd4c7d3f6f6

which does not include a V8 roll. What's shown as the V8 revision in Clusterfuzz is simply the last V8 revision (minus version bumps) at the time of the regression, but it's the same at both ends of the regression range.

Sending back to hablich@ to triage to someone who knows more about investigating GC marking than me. :)
Project Member

Comment 5 by ClusterFuzz, Aug 20 2017

ClusterFuzz has detected this issue as fixed in range 495818:495819.

Detailed report: https://clusterfuzz.com/testcase?key=5977328160342016

Fuzzer: inferno_layout_test_unmodified
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: CHECK failure
Crash Address: 
Crash State:
  IsMarked(object) in mark-compact.cc
  gin::PrintStackTrace
  v8::internal::MarkingVerifier::VerifyMarkingOnPage
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=458024:458029
Fixed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=495818:495819

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5977328160342016

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Aug 20 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5977328160342016 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment