V8 correctness failure in configs: x64,ignition:x64,slow_path |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5264329017131008 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,slow_path sources: 22c Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=51425:51426 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5264329017131008 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Mar 5 2018
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/0d5588dc2cbcfe9303635d757286c14244793dc2 commit 0d5588dc2cbcfe9303635d757286c14244793dc2 Author: Sigurd Schneider <sigurds@chromium.org> Date: Mon Mar 05 15:19:11 2018 [turbofan] Don't drop arguments in fast-path Math fast-path cannot drop arguments because their side-effects must be preserved. For example, Math.imul(x) dropped x entirely, because if x is convertible to an integer, the result is 0. This, however, is not OK because converting x to an integer might throw. Bug: chromium:818070 , v8:7250 , v8:7240 Change-Id: I8363e6dcd3fc78c879395aacb636d5782c3b023e Reviewed-on: https://chromium-review.googlesource.com/948523 Reviewed-by: Jaroslav Sevcik <jarin@chromium.org> Commit-Queue: Sigurd Schneider <sigurds@chromium.org> Cr-Commit-Position: refs/heads/master@{#51736} [modify] https://crrev.com/0d5588dc2cbcfe9303635d757286c14244793dc2/src/compiler/js-call-reducer.cc [add] https://crrev.com/0d5588dc2cbcfe9303635d757286c14244793dc2/test/mjsunit/regress/regress-818070.js
,
Mar 6 2018
ClusterFuzz has detected this issue as fixed in range 51735:51736. Detailed report: https://clusterfuzz.com/testcase?key=5264329017131008 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,slow_path sources: 22c Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=51425:51426 Fixed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=51735:51736 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5264329017131008 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 6 2018
ClusterFuzz testcase 5264329017131008 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Mar 6 2018
|
|||
►
Sign in to add a comment |
|||
Comment 1 by ClusterFuzz
, Mar 2 2018Owner: sigurds@chromium.org
Status: Assigned (was: Untriaged)