Ill in __RT_impl_Runtime_OptimizeFunctionOnNextCall |
||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6445385814638592 Fuzzer: ochang_js_fuzzer Job Type: linux_ubsan_vptr_d8 Platform Id: linux Crash Type: Ill Crash Address: 0x55e1cd54584e Crash State: __RT_impl_Runtime_OptimizeFunctionOnNextCall v8::internal::Runtime_OptimizeFunctionOnNextCall Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_d8&range=51276:51277 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6445385814638592 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Nov 5
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/7621325d797dfdd7ac9ae9f7ab3a1ee1c354bb57 commit 7621325d797dfdd7ac9ae9f7ab3a1ee1c354bb57 Author: Camillo Bruni <cbruni@chromium.org> Date: Mon Nov 05 12:32:05 2018 [runtime] Harden OptimizeFunctionOnNextCall Ignore invalid input for all arguments of OptimizeFunctionOnNextCall potentially produced by fuzzers. Bug: chromium:901645 Change-Id: Ic185812c228a92f8dbb48212c45685bd14892947 Reviewed-on: https://chromium-review.googlesource.com/c/1317567 Reviewed-by: Jakob Gruber <jgruber@chromium.org> Commit-Queue: Camillo Bruni <cbruni@chromium.org> Cr-Commit-Position: refs/heads/master@{#57234} [modify] https://crrev.com/7621325d797dfdd7ac9ae9f7ab3a1ee1c354bb57/src/runtime/runtime-test.cc
,
Nov 6
ClusterFuzz has detected this issue as fixed in range 57233:57234. Detailed report: https://clusterfuzz.com/testcase?key=6445385814638592 Fuzzer: ochang_js_fuzzer Job Type: linux_ubsan_vptr_d8 Platform Id: linux Crash Type: Ill Crash Address: 0x55e1cd54584e Crash State: __RT_impl_Runtime_OptimizeFunctionOnNextCall v8::internal::Runtime_OptimizeFunctionOnNextCall Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_d8&range=51276:51277 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_d8&range=57233:57234 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6445385814638592 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 6
ClusterFuzz testcase 6445385814638592 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by ClusterFuzz
, Nov 4Owner: cbruni@chromium.org
Status: Assigned (was: Untriaged)