New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 784341 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 782280
Owner:
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

CHECK failure: interpreter != liftoff (22302e1 vs NUMBER); WasmCodeFuzzerHash=21aNUMBER in wasm

Project Member Reported by ClusterFuzz, Nov 13 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5325580013928448

Fuzzer: libFuzzer_v8_wasm_compile_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  interpreter != liftoff (22302e1 vs NUMBER); WasmCodeFuzzerHash=21aNUMBER in wasm
  v8::internal::wasm::fuzzer::WasmExecutionFuzzer::FuzzWasmModule
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=514773:514780

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5325580013928448

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Nov 13 2017

Components: Blink>JavaScript
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Nov 13 2017

Labels: Test-Predator-Auto-Owner
Owner: eholk@chromium.org
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/v8/v8/+/41bd98e703d9037d8522ff5d5613314c55a48e6c ([wasm fuzzer] generate grow_memory instructions).

If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.

Comment 3 by eholk@chromium.org, Nov 13 2017

Cc: eholk@chromium.org
Components: Blink>JavaScript>WebAssembly
Owner: clemensh@chromium.org
These are probably all dupes of the original one. Clemens, can you confirm? I'm guessing the fix is in but it may take time to get to all the fuzzers, right?
Mergedinto: 782280
Status: Duplicate (was: Assigned)
Project Member

Comment 5 by ClusterFuzz, Nov 14 2017

ClusterFuzz has detected this issue as fixed in range 515946:515969.

Detailed report: https://clusterfuzz.com/testcase?key=5325580013928448

Fuzzer: libFuzzer_v8_wasm_compile_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  interpreter != liftoff (22302e1 vs NUMBER); WasmCodeFuzzerHash=21aNUMBER in wasm
  v8::internal::wasm::fuzzer::WasmExecutionFuzzer::FuzzWasmModule
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=514773:514780
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=515946:515969

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5325580013928448

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment