Ill in v8::internal::CaptureAsyncStackTrace |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5540563838042112 Fuzzer: ochang_js_fuzzer Job Type: linux_ubsan_vptr_d8 Platform Id: linux Crash Type: Ill Crash Address: 0x55e1d1d168de Crash State: v8::internal::CaptureAsyncStackTrace v8::internal::Isolate::CaptureSimpleStackTrace v8::internal::Isolate::CaptureAndSetSimpleStackTrace Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_d8&range=56612:56613 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5540563838042112 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Oct 19
,
Oct 19
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/e650b9e43e1e035e6dac4a5a2205bcd1d7953ebe commit e650b9e43e1e035e6dac4a5a2205bcd1d7953ebe Author: Benedikt Meurer <bmeurer@chromium.org> Date: Fri Oct 19 08:25:27 2018 [async] Gracefully handle exceptions in async_hooks. When --async-stack-traces is on and there's an exception from within an async_hook "after" handler, we will be faced with a settled promise. In that case we cannot do anything, since the promise will not have any reactions on it anymore, but we should also not crash of course. Bug: chromium:896700 , v8:7522 Change-Id: I6e3d212d0433da40740489ff7421c5a98cf9bff3 Reviewed-on: https://chromium-review.googlesource.com/c/1290550 Reviewed-by: Yang Guo <yangguo@chromium.org> Commit-Queue: Benedikt Meurer <bmeurer@chromium.org> Cr-Commit-Position: refs/heads/master@{#56801} [modify] https://crrev.com/e650b9e43e1e035e6dac4a5a2205bcd1d7953ebe/src/isolate.cc [add] https://crrev.com/e650b9e43e1e035e6dac4a5a2205bcd1d7953ebe/test/mjsunit/regress/regress-crbug-896700.js
,
Oct 20
ClusterFuzz has detected this issue as fixed in range 56800:56801. Detailed report: https://clusterfuzz.com/testcase?key=5540563838042112 Fuzzer: ochang_js_fuzzer Job Type: linux_ubsan_vptr_d8 Platform Id: linux Crash Type: Ill Crash Address: 0x55e1d1d168de Crash State: v8::internal::CaptureAsyncStackTrace v8::internal::Isolate::CaptureSimpleStackTrace v8::internal::Isolate::CaptureAndSetSimpleStackTrace Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_d8&range=56612:56613 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_d8&range=56800:56801 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5540563838042112 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 20
ClusterFuzz testcase 5540563838042112 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by ClusterFuzz
, Oct 18Owner: bmeu...@chromium.org
Status: Assigned (was: Untriaged)