V8 correctness failure in configs: x64,ignition:x64,ignition_turbo |
||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5109413739495424 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,ignition_turbo sources: a1d Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=43348:43349 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5109413739495424 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Dec 13 2017
Error message difference between turbo and ignition. Goes back too far in time... dropping this on compiler triage queue.
,
Dec 13 2017
This is Caught: __v_2.apply is not a function versus Caught: Function.prototype.apply was called on #<Object>, which is a object and not a function This seems to be the CallWithArrayLike vs. CallForwardVarargs problem. The latter we also use for spread calls, so it's not as easy as just having a different exception there.
,
Mar 21 2018
Issue 799116 has been merged into this issue.
,
Apr 5 2018
,
May 15 2018
,
May 15 2018
,
Jul 18
,
Jul 20
ClusterFuzz testcase 5072932293050368 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jul 20
Nah, not fixed, just the foozzie config changed. Reopening. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by ClusterFuzz
, Dec 13 2017Owner: machenb...@chromium.org
Status: Assigned (was: Untriaged)