New issue
Advanced search Search tips

Issue 772649 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Oct 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Ill in v8::internal::TranslatedState::MaterializeCapturedObjectAt

Project Member Reported by ClusterFuzz, Oct 7 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4930677039693824

Fuzzer: ochang_js_fuzzer
Job Type: linux_asan_d8_dbg
Platform Id: linux

Crash Type: Ill
Crash Address: 0x7fc924148988
Crash State:
  v8::internal::TranslatedState::MaterializeCapturedObjectAt
  v8::internal::TranslatedState::MaterializeAt
  MaterializeObjectAt
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_dbg&range=48067:48068

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4930677039693824

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Oct 7 2017

Labels: Test-Predator-AutoOwner
Owner: ca...@igalia.com
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/v8/v8/+/88a4cf736ef10b213d2e29a841ac73934b8eccc7 ([esnext] ship --harmony-async-iteration).

If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.

Comment 2 by ca...@igalia.com, Oct 7 2017

Fix submitted for review. https://chromium-review.googlesource.com/c/v8/v8/+/706780
Project Member

Comment 3 by bugdroid1@chromium.org, Oct 10 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/v8/v8.git/+/9f0bdf044fc8ba7dd8e3b455d01a055cf698d96f

commit 9f0bdf044fc8ba7dd8e3b455d01a055cf698d96f
Author: Caitlin Potter <caitp@igalia.com>
Date: Tue Oct 10 11:18:10 2017

[esnext] fix MaterializeCapturedObjectAt for async generator objects

Previously, JS_ASYNC_GENERATOR_OBJECT_TYPE maps led to an UNREACHABLE
macro, but are now restored like ordinary JSGeneratorObjects.

BUG= chromium:772649 ,  v8:5855 
R=adamk@chromium.org, yangguo@chromium.org, verwaest@chromium.org

Change-Id: I02e101565625f8a057d0e5b242a5fe0df263df89
Reviewed-on: https://chromium-review.googlesource.com/706780
Commit-Queue: Caitlin Potter <caitp@igalia.com>
Reviewed-by: Jaroslav Sevcik <jarin@chromium.org>
Reviewed-by: Yang Guo <yangguo@chromium.org>
Cr-Commit-Position: refs/heads/master@{#48423}
[modify] https://crrev.com/9f0bdf044fc8ba7dd8e3b455d01a055cf698d96f/src/deoptimizer.cc
[add] https://crrev.com/9f0bdf044fc8ba7dd8e3b455d01a055cf698d96f/test/mjsunit/harmony/regress/regress-772649.js

Project Member

Comment 4 by ClusterFuzz, Oct 11 2017

ClusterFuzz has detected this issue as fixed in range 48422:48423.

Detailed report: https://clusterfuzz.com/testcase?key=4930677039693824

Fuzzer: ochang_js_fuzzer
Job Type: linux_asan_d8_dbg
Platform Id: linux

Crash Type: Ill
Crash Address: 0x7fc924148988
Crash State:
  v8::internal::TranslatedState::MaterializeCapturedObjectAt
  v8::internal::TranslatedState::MaterializeAt
  MaterializeObjectAt
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_dbg&range=48067:48068
Fixed: https://clusterfuzz.com/revisions?job=linux_asan_d8_dbg&range=48422:48423

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4930677039693824

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Oct 11 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 4930677039693824 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Labels: -Test-Predator-AutoOwner Test-Predator-Auto-Owner

Sign in to add a comment