Skip to content

VM crash with SEGV_MAPERR on dart-fuzz bot #60850

Open
@alexmarkov

Description

@alexmarkov

From dart-fuzz bot:

===== CRASH =====
si_signo=Segmentation fault(11), si_code=SEGV_MAPERR(1), si_addr=0x27daadd



-- BEGIN REPRODUCE  --

DART SDK REVISION: 

dart runtime/tools/dartfuzz/dartfuzz.dart --no-fp --no-ffi --flat --seed 656373376 fuzz.dart

-- RUN 1 --

out/ReleaseX64C/dart --profiler --force_evacuation --no_array_bounds_check_elimination --old_gen_heap_size=128 /b/s/w/it31rrdx0s/dart_fuzzUACCYQ/fuzz.dart

-- RUN 2 --

out/DebugSIMARM/dart --profiler --profile_vm=false --profile_vm=false --verify_after_gc --compactor_tasks=2 --no_enable_peephole --inlining_hotness=15 --old_gen_heap_size=128 /b/s/w/it31rrdx0s/dart_fuzzUACCYQ/fuzz.dart

-- END REPRODUCE  --

Log: https://logs.chromium.org/logs/dart/buildbucket/cr-buildbucket/8713113813214013105/+/u/collect_shards/dartfuzz_-_generated_programs_shard_3/task_stdout_stderr:_dartfuzz_-_generated_programs_shard_3

Another dart-fuzz shard crashed differently, but these crashes could be related: #60809 (comment)

Metadata

Metadata

Assignees

Labels

area-vmUse area-vm for VM related issues, including code coverage, and the AOT and JIT backends.crashProcess exits with SIGSEGV, SIGABRT, etc. An unhandled exception is not a crash.dartfuzzFound with Dart fuzzing (DartFuzz, libFuzzer, etc.)gardeningtriagedIssue has been triaged by sub team

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions