!v8::internal::FLAG_enable_slow_asserts || (object->IsJSObject()) in src/objects |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5789061444272128 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_ignition_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !v8::internal::FLAG_enable_slow_asserts || (object->IsJSObject()) in src/objects Minimized Testcase (8.75 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95z2mtGzjTHnW2ohkNE2B06D-rG5QgOVOCnLgGGWT_R2AgLA3tVBCgV3Y4SbWUi2Kc8r6a74KdHRdPCnwTkfLRVRS2D_6eAYyzX_qqKbTzxMa0-ogDU2y9Bs9sKwxnb6IdOaU3rwQr0o1K6VVVGeMnoaNtDPA Filer: mstarzinger See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
May 13 2016
,
Jun 22 2016
,
Jun 22 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/bbbf21c240918ef70384c58d5aaa2ee12af6bfc1 commit bbbf21c240918ef70384c58d5aaa2ee12af6bfc1 Author: ishell <ishell@chromium.org> Date: Wed Jun 22 11:22:48 2016 Don't crash when trying to print a call stack of an OOM. Receiver is the hole when we construct a builtin object. BUG= chromium:611684 Review-Url: https://codereview.chromium.org/2083163003 Cr-Commit-Position: refs/heads/master@{#37182} [modify] https://crrev.com/bbbf21c240918ef70384c58d5aaa2ee12af6bfc1/src/string-stream.cc
,
Jun 22 2016
,
Jun 22 2016
ClusterFuzz has detected this issue as fixed in range 37181:37182. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5789061444272128 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_ignition_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !v8::internal::FLAG_enable_slow_asserts || (object->IsJSObject()) in objects-inl Fixed: V8: r37181:37182 Minimized Testcase (8.75 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94yDjRdYFfoupT8OWl9xg1JKffCvQSzhnF5Esj0Fl7tKVXbhsgcjZmwV7NX7jqVvCpCVOCx812h1QQEK5VG-k0dVJaOGkhCtpzgf6cUlu0o-HGIfk0MyzFHVOo_qJ_8O0TdgTqS-5exsiOJ99VsAJ_gZSnjvg?testcase_id=5789061444272128 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jun 22 2016
ClusterFuzz has detected this issue as fixed in range 37181:37182. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5789061444272128 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_ignition_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !v8::internal::FLAG_enable_slow_asserts || (object->IsJSObject()) in objects-inl Fixed: V8: r37181:37182 Minimized Testcase (8.75 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94yDjRdYFfoupT8OWl9xg1JKffCvQSzhnF5Esj0Fl7tKVXbhsgcjZmwV7NX7jqVvCpCVOCx812h1QQEK5VG-k0dVJaOGkhCtpzgf6cUlu0o-HGIfk0MyzFHVOo_qJ_8O0TdgTqS-5exsiOJ99VsAJ_gZSnjvg?testcase_id=5789061444272128 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by mstarzinger@chromium.org
, May 13 2016