New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 784172 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 782280
Owner:
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

CHECK failure: interpreter != liftoff (fffffed7 vs ff3e9ed3); WasmCodeFuzzerHash=4ce061fa in wa

Project Member Reported by ClusterFuzz, Nov 12 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5736142245986304

Fuzzer: libFuzzer_v8_wasm_compile_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  interpreter != liftoff (fffffed7 vs ff3e9ed3); WasmCodeFuzzerHash=4ce061fa in wa
  v8::internal::wasm::fuzzer::WasmExecutionFuzzer::FuzzWasmModule
  _start
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=514774:514785

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5736142245986304

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Nov 12 2017

Components: Blink>JavaScript
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Nov 12 2017

Labels: Test-Predator-Auto-Owner
Owner: eholk@chromium.org
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/v8/v8/+/41bd98e703d9037d8522ff5d5613314c55a48e6c ([wasm fuzzer] generate grow_memory instructions).

If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.

Comment 3 by eholk@chromium.org, Nov 13 2017

Cc: eholk@chromium.org
Components: Blink>JavaScript>WebAssembly
Owner: clemensh@chromium.org
These are probably all dupes of the original one. Clemens, can you confirm? I'm guessing the fix is in but it may take time to get to all the fuzzers, right?
Mergedinto: 782280
Status: Duplicate (was: Assigned)
Project Member

Comment 5 by ClusterFuzz, Nov 14 2017

ClusterFuzz has detected this issue as fixed in range 515947:515970.

Detailed report: https://clusterfuzz.com/testcase?key=5736142245986304

Fuzzer: libFuzzer_v8_wasm_compile_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  interpreter != liftoff (fffffed7 vs ff3e9ed3); WasmCodeFuzzerHash=4ce061fa in wa
  v8::internal::wasm::fuzzer::WasmExecutionFuzzer::FuzzWasmModule
  _start
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=514774:514785
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=515947:515970

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5736142245986304

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment