Status: Untriaged
Owner: ----
Labels: Hotlist-FlagFuzz
Components: GarbageCollection WebAssembly
Priority: 1
Type: Bug
New issue 14297 by mache...@
chromium.org: mjsunit/wasm/wasm-to-js starts failing (flag fuzzer)
https://bugs.chromium.org/p/v8/issues/detail?id=14297Failing test: mjsunit/wasm/wasm-to-js
Failure link:
https://cr-buildbucket.appspot.com/build/8770886406492678177Link to Flako run:
https://ci.chromium.org/ui/p/v8/builders/try.triggered/v8_flako/b8770859525997178673/overviewCrash type: DCHECK failure
Crash state:
kCanBeWeak || (!IsSmi() == HAS_STRONG_HEAP_OBJECT_TAG(ptr_)) in tagged-impl.h
Error summary:
#
# Fatal error in ../../src/objects/tagged-impl.h, line 144
# Debug check failed: kCanBeWeak || (!IsSmi() == HAS_STRONG_HEAP_OBJECT_TAG(ptr_)).
#
#
#
#FailureMessage Object: 0x7ffddca83610
==== C stack trace ===============================
/b/s/w/ir/out/build/libv8_libbase.so(v8::base::debug::StackTrace::StackTrace()+0x13) [0x7f1235ee35a3]
/b/s/w/ir/out/build/libv8_libplatform.so(+0x19b7d) [0x7f12319f2b7d]
/b/s/w/ir/out/build/libv8_libbase.so(V8_Fatal(char const*, int, char const*, ...)+0x154) [0x7f1235ec3264]
/b/s/w/ir/out/build/libv8_libbase.so(+0x2bd05) [0x7f1235ec2d05]
/b/s/w/ir/out/build/libv8.so(v8::internal::Object::VerifyPointer(v8::internal::Isolate*, v8::internal::Tagged<v8::internal::Object>)+0x44) [0x7f1233c29664]
/b/s/w/ir/out/build/libv8.so(v8::internal::TorqueGeneratedClassVerifiers::FixedArrayVerify(v8::internal::FixedArray, v8::internal::Isolate*)+0xa7) [0x7f12352729b7]
/b/s/w/ir/out/build/libv8.so(v8::internal::FixedArray::FixedArrayVerify(v8::internal::Isolate*)+0x1f) [0x7f1233c2a9cf]
/b/s/w/ir/out/build/libv8.so(v8::internal::HeapObject::HeapObjectVerify(v8::internal::Isolate*)+0xa21) [0x7f1233c28011]
/b/s/w/ir/out/build/libv8.so(v8::internal::Object::ObjectVerify(v8::internal::Tagged<v8::internal::Object>, v8::internal::Isolate*)+0xe6) [0x7f1233c27166]
Crash analysis hash: 173e3c3d35feb36a58a448ec3c840f0f
--
You received this message because:
1. The project was configured to send all issue notifications to this address
You may adjust your notification preferences at:
https://bugs.chromium.org/hosting/settings