Issue metadata
Sign in to add a comment
|
V8 correctness failure in configs: x64,ignition:x64,ignition_turbo |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6666687756369920 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,ignition_turbo sources: b2b Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=51672:51673 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6666687756369920 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
May 3 2018
Looks like a dupe of https://crbug.com/823130 , which is hard to repro. Feel free to mark as duplicate. Dunno, why clusterfuzz bisects it to this CL. Probably a bit flaky on clusterfuzz too.
,
May 3 2018
,
May 3 2018
Thanks for the analysis! Marking as dupe.
The reason this particular repro bisects to the "Stage BigInt" CL is because it contains an (unused and irrelevant) load early on in the test:
BigIntPrototypeValueOf = BigInt.prototype.valueOf;
which isn't wrapped in a try..catch, so before the BigInt CL that would prevent it from doing anything interesting.
,
May 4 2018
ClusterFuzz has detected this issue as fixed in range 52973:52974. Detailed report: https://clusterfuzz.com/testcase?key=6666687756369920 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,ignition_turbo sources: b2b Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=51672:51673 Fixed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=52973:52974 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6666687756369920 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, May 3 2018Owner: jkummerow@chromium.org
Status: Assigned (was: Untriaged)