New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 782280 link

Starred by 3 users

Issue metadata

Status: Fixed
Owner:
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug

Blocking:
issue v8:6600



Sign in to add a comment

CHECK failure: interpreter != liftoff (ec35c0be vs ebeNUMBER); WasmCodeFuzzerHash=ee207cda in w

Project Member Reported by ClusterFuzz, Nov 7 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5906530846375936

Fuzzer: libFuzzer_v8_wasm_compile_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  interpreter != liftoff (ec35c0be vs ebeNUMBER); WasmCodeFuzzerHash=ee207cda in w
  v8::internal::wasm::fuzzer::WasmExecutionFuzzer::FuzzWasmModule
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=514357:514376

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5906530846375936

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Showing comments 12 - 111 of 111 Older
Cc: eholk@chromium.org clemensh@chromium.org
 Issue 782818  has been merged into this issue.
 Issue 782768  has been merged into this issue.
 Issue 782764  has been merged into this issue.
 Issue 782762  has been merged into this issue.
 Issue 782750  has been merged into this issue.
 Issue 782746  has been merged into this issue.
 Issue 782741  has been merged into this issue.
 Issue 782774  has been merged into this issue.
 Issue 782736  has been merged into this issue.
 Issue 782683  has been merged into this issue.
 Issue 782682  has been merged into this issue.
 Issue 782680  has been merged into this issue.
 Issue 782675  has been merged into this issue.
 Issue 782668  has been merged into this issue.
 Issue 782667  has been merged into this issue.
 Issue 782653  has been merged into this issue.
 Issue 782652  has been merged into this issue.
 Issue 782648  has been merged into this issue.
 Issue 782645  has been merged into this issue.
 Issue 782644  has been merged into this issue.
 Issue 782620  has been merged into this issue.
 Issue 782605  has been merged into this issue.
 Issue 782600  has been merged into this issue.
 Issue 782595  has been merged into this issue.
 Issue 782289  has been merged into this issue.
 Issue 782279  has been merged into this issue.
 Issue 782200  has been merged into this issue.
 Issue 782177  has been merged into this issue.
 Issue 782203  has been merged into this issue.
 Issue 782204  has been merged into this issue.
 Issue 782207  has been merged into this issue.
 Issue 782612  has been merged into this issue.
 Issue 782263  has been merged into this issue.
 Issue 782264  has been merged into this issue.
 Issue 782266  has been merged into this issue.
 Issue 782267  has been merged into this issue.
Project Member

Comment 49 by ClusterFuzz, Nov 9 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Started)
ClusterFuzz testcase 5016944603561984 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 50 by ClusterFuzz, Nov 9 2017

ClusterFuzz has detected this issue as fixed in range 514773:514780.

Detailed report: https://clusterfuzz.com/testcase?key=5906530846375936

Fuzzer: libFuzzer_v8_wasm_compile_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  interpreter != liftoff (ec35c0be vs ebeNUMBER); WasmCodeFuzzerHash=ee207cda in w
  v8::internal::wasm::fuzzer::WasmExecutionFuzzer::FuzzWasmModule
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=514357:514376
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=514773:514780

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5906530846375936

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
 Issue 782779  has been merged into this issue.
Labels: ClusterFuzz-Wrong
Status: Started (was: Verified)
Signature changed because of a change in the fuzzer. The original issue is not fixed yet.
CL is ready, see #12.
 Issue 782822  has been merged into this issue.
 Issue 782829  has been merged into this issue.
 Issue 783061  has been merged into this issue.
 Issue 783203  has been merged into this issue.
 Issue 783202  has been merged into this issue.
 Issue 783196  has been merged into this issue.
 Issue 783138  has been merged into this issue.
 Issue 782745  has been merged into this issue.
 Issue 783240  has been merged into this issue.
 Issue 783238  has been merged into this issue.
 Issue 783236  has been merged into this issue.
 Issue 783277  has been merged into this issue.
 Issue 783279  has been merged into this issue.
 Issue 783579  has been merged into this issue.
 Issue 783594  has been merged into this issue.
 Issue 783591  has been merged into this issue.
 Issue 783556  has been merged into this issue.
 Issue 783511  has been merged into this issue.
 Issue 783502  has been merged into this issue.
 Issue 783501  has been merged into this issue.
 Issue 783488  has been merged into this issue.
 Issue 783475  has been merged into this issue.
 Issue 783474  has been merged into this issue.
 Issue 783469  has been merged into this issue.
 Issue 783465  has been merged into this issue.
 Issue 783463  has been merged into this issue.
 Issue 783462  has been merged into this issue.
 Issue 783461  has been merged into this issue.
 Issue 783457  has been merged into this issue.
 Issue 783456  has been merged into this issue.
 Issue 783453  has been merged into this issue.
 Issue 783356  has been merged into this issue.
 Issue 783348  has been merged into this issue.
 Issue 783343  has been merged into this issue.
 Issue 783332  has been merged into this issue.
 Issue 783331  has been merged into this issue.
 Issue 783324  has been merged into this issue.
 Issue 783322  has been merged into this issue.
 Issue 783305  has been merged into this issue.
 Issue 783302  has been merged into this issue.
 Issue 783245  has been merged into this issue.
Project Member

Comment 94 by bugdroid1@chromium.org, Nov 10 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/v8/v8.git/+/6c6132880adf636960f47662570766ab424be534

commit 6c6132880adf636960f47662570766ab424be534
Author: Clemens Hammacher <clemensh@chromium.org>
Date: Fri Nov 10 09:47:32 2017

[Liftoff] Implement parallel register moves

This was not implemented so far, leading to lots of clusterfuzz issues.
Testing this feature would require complicating the interface a lot and
exposing more implementation details in the header file, hence we just
go with regression tests for now.

R=ahaas@chromium.org, titzer@chromium.org

Bug: v8:6600,  chromium:782280 
Change-Id: I12863f3eb59a8dffdcc7d3bfb8e1f0ae0eec15ee
Reviewed-on: https://chromium-review.googlesource.com/758772
Reviewed-by: Andreas Haas <ahaas@chromium.org>
Commit-Queue: Clemens Hammacher <clemensh@chromium.org>
Cr-Commit-Position: refs/heads/master@{#49286}
[modify] https://crrev.com/6c6132880adf636960f47662570766ab424be534/src/wasm/baseline/liftoff-assembler.cc
[add] https://crrev.com/6c6132880adf636960f47662570766ab424be534/test/mjsunit/regress/wasm/regress-782280.js

Status: Fixed (was: Started)
Status: Started (was: Fixed)
Reverted, have to reland after fix.
Project Member

Comment 97 by bugdroid1@chromium.org, Nov 10 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/v8/v8.git/+/5a6cc315f843a3a6fc37e54069f19aa7164c78a4

commit 5a6cc315f843a3a6fc37e54069f19aa7164c78a4
Author: Clemens Hammacher <clemensh@chromium.org>
Date: Fri Nov 10 10:04:35 2017

Revert "[Liftoff] Implement parallel register moves"

This reverts commit 6c6132880adf636960f47662570766ab424be534.

Reason for revert: breaks compilation on win64 bot: https://build.chromium.org/p/client.v8/builders/V8%20Win64%20-%20msvc/builds/69

Original change's description:
> [Liftoff] Implement parallel register moves
> 
> This was not implemented so far, leading to lots of clusterfuzz issues.
> Testing this feature would require complicating the interface a lot and
> exposing more implementation details in the header file, hence we just
> go with regression tests for now.
> 
> R=​ahaas@chromium.org, titzer@chromium.org
> 
> Bug: v8:6600,  chromium:782280 
> Change-Id: I12863f3eb59a8dffdcc7d3bfb8e1f0ae0eec15ee
> Reviewed-on: https://chromium-review.googlesource.com/758772
> Reviewed-by: Andreas Haas <ahaas@chromium.org>
> Commit-Queue: Clemens Hammacher <clemensh@chromium.org>
> Cr-Commit-Position: refs/heads/master@{#49286}

TBR=titzer@chromium.org,ahaas@chromium.org,clemensh@chromium.org

Change-Id: I386983da7f9f03d54cef2190b01fd2cc5785966e
No-Presubmit: true
No-Tree-Checks: true
No-Try: true
Bug: v8:6600,  chromium:782280 
Reviewed-on: https://chromium-review.googlesource.com/763367
Reviewed-by: Clemens Hammacher <clemensh@chromium.org>
Commit-Queue: Clemens Hammacher <clemensh@chromium.org>
Cr-Commit-Position: refs/heads/master@{#49289}
[modify] https://crrev.com/5a6cc315f843a3a6fc37e54069f19aa7164c78a4/src/wasm/baseline/liftoff-assembler.cc
[delete] https://crrev.com/9eaf163d6f3a0b744de1a45047674fea7004af63/test/mjsunit/regress/wasm/regress-782280.js

 Issue 783664  has been merged into this issue.
 Issue 783712  has been merged into this issue.
Project Member

Comment 100 by bugdroid1@chromium.org, Nov 10 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/v8/v8.git/+/359e69e183f495f160cde9206761ada3634a7e55

commit 359e69e183f495f160cde9206761ada3634a7e55
Author: Clemens Hammacher <clemensh@chromium.org>
Date: Fri Nov 10 12:18:08 2017

Reland "[Liftoff] Implement parallel register moves"

This is a reland of 6c6132880adf636960f47662570766ab424be534
Original change's description:
> [Liftoff] Implement parallel register moves
> 
> This was not implemented so far, leading to lots of clusterfuzz issues.
> Testing this feature would require complicating the interface a lot and
> exposing more implementation details in the header file, hence we just
> go with regression tests for now.
> 
> R=ahaas@chromium.org, titzer@chromium.org
> 
> Bug: v8:6600,  chromium:782280 
> Change-Id: I12863f3eb59a8dffdcc7d3bfb8e1f0ae0eec15ee
> Reviewed-on: https://chromium-review.googlesource.com/758772
> Reviewed-by: Andreas Haas <ahaas@chromium.org>
> Commit-Queue: Clemens Hammacher <clemensh@chromium.org>
> Cr-Commit-Position: refs/heads/master@{#49286}

Bug: v8:6600,  chromium:782280 
Change-Id: I82a75bfeaf83dc63a2917da3ccdc4721c5d689e7
Reviewed-on: https://chromium-review.googlesource.com/763387
Reviewed-by: Andreas Haas <ahaas@chromium.org>
Commit-Queue: Clemens Hammacher <clemensh@chromium.org>
Cr-Commit-Position: refs/heads/master@{#49292}
[modify] https://crrev.com/359e69e183f495f160cde9206761ada3634a7e55/src/wasm/baseline/liftoff-assembler.cc
[add] https://crrev.com/359e69e183f495f160cde9206761ada3634a7e55/test/mjsunit/regress/wasm/regress-782280.js

Blocking: v8:6600
Status: Fixed (was: Started)
\
 Issue 783276  has been merged into this issue.
 Issue 784371  has been merged into this issue.
 Issue 784364  has been merged into this issue.
 Issue 784357  has been merged into this issue.
 Issue 784346  has been merged into this issue.
 Issue 784343  has been merged into this issue.
Cc: v8-autoroll@chromium.org
 Issue 784143  has been merged into this issue.
 Issue 784144  has been merged into this issue.
 Issue 784149  has been merged into this issue.
 Issue 784150  has been merged into this issue.
 Issue 784157  has been merged into this issue.
 Issue 784160  has been merged into this issue.
 Issue 784170  has been merged into this issue.
 Issue 784172  has been merged into this issue.
 Issue 784175  has been merged into this issue.
 Issue 784176  has been merged into this issue.
 Issue 784239  has been merged into this issue.
 Issue 784341  has been merged into this issue.
Cc: msrchandra@chromium.org pnangunoori@chromium.org
 Issue 784635  has been merged into this issue.
 Issue 784535  has been merged into this issue.
 Issue 784538  has been merged into this issue.
 Issue 784539  has been merged into this issue.
 Issue 784541  has been merged into this issue.
 Issue 784544  has been merged into this issue.
 Issue 784545  has been merged into this issue.
 Issue 784625  has been merged into this issue.
 Issue 784634  has been merged into this issue.
 Issue 784642  has been merged into this issue.
 Issue 784644  has been merged into this issue.
 Issue 784704  has been merged into this issue.
 Issue 784708  has been merged into this issue.
 Issue 784712  has been merged into this issue.
Showing comments 12 - 111 of 111 Older

Sign in to add a comment