New issue
Advanced search Search tips

Issue 860680 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Sep 19
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Fatal error in verifier.cc

Project Member Reported by ClusterFuzz, Jul 6

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5286025870704640

Fuzzer: binaryen_wasm_fuzzer
Job Type: linux_asan_d8_v8_arm_dbg
Platform Id: linux

Crash Type: Fatal error
Crash Address: 
Crash State:
  verifier.cc
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5286025870704640

No crash found using linux_d8_dbg job.

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.

Note: This crash might not be reproducible with the provided testcase. That said, for the past 14 days we've been seeing this crash frequently. If you are unable to reproduce this, please try a speculative fix based on the crash stacktrace in the report. The fix can be verified by looking at the crash statistics in the report, a day after the fix is deployed. We will auto-close the bug if the crash is not seen for 14 days.
 
Project Member

Comment 1 by ClusterFuzz, Jul 17

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://clusterfuzz.com/testcase?key=5015985883709440.
Project Member

Comment 2 by ClusterFuzz, Jul 17

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://clusterfuzz.com/testcase?key=5189487907569664.
Project Member

Comment 3 by ClusterFuzz, Jul 17

Labels: Fuzz-Blocker ReleaseBlock-Beta M-69
This crash occurs very frequently on linux platform and is likely preventing the fuzzer  from making much progress. Fixing this will allow more bugs to be found.

Marking this bug as a blocker for next Beta release.

If this is incorrect, please add ClusterFuzz-Wrong label and remove the ReleaseBlock-Beta label.
M69 branch is coming VERY soon on this Thursday, July 19th, Your bug is marked as ReleaseBlock-Beta for M69. Please try to land the fix ASAP to trunk in order to prevent many merges going after M69 branch. This will also help us to branch M69 from high quality trunk. Thank you.
Labels: -Pri-1 -ReleaseBlock-Beta -M-69 ClusterFuzz-Wrong Pri-2
This uses experimental wasm features, it's not a release blocker.
Project Member

Comment 6 by ClusterFuzz, Jul 18

Components: Blink>JavaScript>Compiler
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 7 by ClusterFuzz, Jul 18

Detailed report: https://clusterfuzz.com/testcase?key=5189487907569664

Job Type: linux_asan_d8_v8_arm_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  input_count == node->InputCount() in verifier.cc
  v8::internal::compiler::Verifier::Visitor::Check
  v8::internal::compiler::Verifier::Run
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5189487907569664

See https://github.com/google/clusterfuzz-tools for more information.
Components: -Blink>JavaScript -Blink>JavaScript>Compiler Blink>JavaScript>WebAssembly
Owner: gdeepti@chromium.org
Status: Assigned (was: Untriaged)
Project Member

Comment 9 by ClusterFuzz, Jul 30

Summary: <no crash state available> (was: Fatal error in verifier.cc)
Testcase 5015985883709440 failed to reproduce the crash. Please inspect the program output at https://clusterfuzz.com/testcase?key=5015985883709440.
Summary: Fatal error in verifier.cc (was: <no crash state available>)
Project Member

Comment 11 by ClusterFuzz, Aug 10

ClusterFuzz has detected this issue as fixed in range 55026:55027.

Detailed report: https://clusterfuzz.com/testcase?key=5189487907569664

Job Type: linux_asan_d8_v8_arm_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  input_count == node->InputCount() in verifier.cc
  v8::internal::compiler::Verifier::Visitor::Check
  v8::internal::compiler::Verifier::Run
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_v8_arm_dbg&range=53500:53501
Fixed: https://clusterfuzz.com/revisions?job=linux_asan_d8_v8_arm_dbg&range=55026:55027

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5189487907569664

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Status: Fixed (was: Assigned)

Sign in to add a comment