V8 correctness failure in configs: x64,ignition:x64,ignition_turbo |
|||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5809014293397504 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,ignition_turbo sources: 7ef Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=45770:45771 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5809014293397504 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Oct 2 2017
Pretty sure this is the same as issue chromium:769852 , I'll hold this.
,
Oct 5 2017
I was jumping to conclusions in comment #2, this is a different issue. But it is only a difference in error messages here. In TurboFan we properly render the call-site whereas in the builtin stub we just use the given string directly as part of the TypeError. Both cases properly throw a TypeError. Lowering priority.
,
Oct 9 2017
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/bb46a592d09c9e513d44bb598947b6aefac66c22 commit bb46a592d09c9e513d44bb598947b6aefac66c22 Author: Michael Starzinger <mstarzinger@chromium.org> Date: Mon Oct 09 12:05:28 2017 [turbofan] Unify error message on non-callable callback. R=mvstanton@chromium.org BUG= chromium:770581 TEST=mjsunit/regress/regress-crbug-770581 Change-Id: I3a5854b6534e67da3e28d9c713830808013675b5 Reviewed-on: https://chromium-review.googlesource.com/702378 Reviewed-by: Michael Stanton <mvstanton@chromium.org> Commit-Queue: Michael Starzinger <mstarzinger@chromium.org> Cr-Commit-Position: refs/heads/master@{#48375} [modify] https://crrev.com/bb46a592d09c9e513d44bb598947b6aefac66c22/src/compiler/js-call-reducer.cc [add] https://crrev.com/bb46a592d09c9e513d44bb598947b6aefac66c22/test/mjsunit/regress/regress-crbug-770581.js
,
Oct 9 2017
,
Oct 10 2017
ClusterFuzz has detected this issue as fixed in range 48374:48375. Detailed report: https://clusterfuzz.com/testcase?key=5809014293397504 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,ignition_turbo sources: 7ef Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=45770:45771 Fixed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=48374:48375 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5809014293397504 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 10 2017
ClusterFuzz testcase 5809014293397504 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by machenb...@chromium.org
, Oct 2 2017Labels: -Pri-1 Pri-2
Owner: danno@chromium.org
Status: Assigned (was: Untriaged)