Issue metadata
Sign in to add a comment
|
DCHECK failure in IsTyped(node) in node-properties.h |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5420818766233600 Fuzzer: ochang_js_fuzzer Job Type: linux_d8_dbg Platform Id: linux Crash Type: DCHECK failure Crash Address: Crash State: IsTyped(node) in node-properties.h Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_d8_dbg&range=49327:49328 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5420818766233600 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Nov 13 2017
,
Nov 14 2017
Reverted CL that caused it. commit ebe6d7a97f962c18595a2a1efaa93fa1c5ede604 (HEAD -> master, origin/master, origin/HEAD) Author: Michael Stanton <mvstanton@chromium.org> Date: Tue Nov 14 09:26:37 2017 +0000 Revert "[TurboFan] Diagnostic code to track down bug in representation selection" This reverts commit f010b28fbe3d117519720aa94ca9e56d3b913d1b. Reason for revert: Introduces a clusterfuzz issue and CAnary crash Original change's description: > [TurboFan] Diagnostic code to track down bug in representation selection > > We need to characterize the types of dead (IrOpcode::kDead) nodes > introduced in compilation phases prior to representation selection. > Normally, a dead node isn't expected at the start of this phase. The > question is, which phase introduced the dead node and failed to > deal with it properly? > > Bug: chromium:780658 > Change-Id: Ief5b45480bb7d704a2d09dafd60b5d389e0fd42e > Reviewed-on: https://chromium-review.googlesource.com/765968 > Reviewed-by: Michael Starzinger <mstarzinger@chromium.org> > Commit-Queue: Michael Stanton <mvstanton@chromium.org> > Cr-Commit-Position: refs/heads/master@{#49328} TBR=mvstanton@chromium.org,mstarzinger@chromium.org Change-Id: I5d628eb1de630ce4a353b6ef0f80fd74ad740f17 No-Presubmit: true No-Tree-Checks: true No-Try: true Bug: chromium:780658 Reviewed-on: https://chromium-review.googlesource.com/768747 Reviewed-by: Michael Stanton <mvstanton@chromium.org> Commit-Queue: Michael Stanton <mvstanton@chromium.org> Cr-Commit-Position: refs/heads/master@{#49347}
,
Nov 14 2017
,
Nov 14 2017
Automatically applying components based on crash stacktrace and information from OWNERS files. If this is incorrect, please apply the Test-Predator-Wrong-Components label.
,
Nov 15 2017
ClusterFuzz has detected this issue as fixed in range 49346:49347. Detailed report: https://clusterfuzz.com/testcase?key=5420818766233600 Fuzzer: ochang_js_fuzzer Job Type: linux_d8_dbg Platform Id: linux Crash Type: DCHECK failure Crash Address: Crash State: IsTyped(node) in node-properties.h Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_d8_dbg&range=49327:49328 Fixed: https://clusterfuzz.com/revisions?job=linux_d8_dbg&range=49346:49347 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5420818766233600 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 15 2017
ClusterFuzz testcase 5420818766233600 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Feb 20 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 27 2018
,
Jul 28
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Nov 13 2017Owner: mvstan...@chromium.org
Status: Assigned (was: Untriaged)