New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 679737 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 679735
Owner:
Closed: Jan 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

index >= 0 && index < length() in objects-inl.h

Project Member Reported by ClusterFuzz, Jan 10 2017

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6098341713936384

Fuzzer: mbarbella_js_mutation
Job Type: linux_asan_d8_v8_mipsel_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  index >= 0 && index < length() in objects-inl.h
  
Sanitizer: address (ASAN)

Regressed: V8: r42167:42168

Minimized Testcase (0.35 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97QwuwoTx23eYEJeH371PlQ9zQa1YxB-jFmW1X5JRJ32hmUs68oMlFzrf_cIspE0k-WIPZCAwTwQlMmWaqI-AkvTvTP-eIZ8HiZXmNsXE6DVh30rUKeWF3bFAouMyauE8K66O3osmqzTp1py8KwGbB2KEtP_EnUKLd_ed9Mvyn1i384MXgmnHKkTc-rEvLmwEH8_k79NnaDc4gN22sX_veMLFKasD_SeD5aw03f2Z6VK_id6W9ju9mSjzWL4MzjjsD5TgvUeV2jK94f9TQ_UTrXNcVPk7Yjk-3ygS4kYSFfKROKBs89BzAZG3F9dklj-hZ29IbAIb6I9V5pqu8Nm0Cc9gti7uF8A49Lwb485Ib4KTDIILc6IuHaOJZu8yqsDVsS5zmwQWFyuwmEgwu5FFn9dyHWIg?testcase_id=6098341713936384
var __v_8 = {};
var __v_10 = {};
var __v_11 = {};
var __v_12 = {};
function __f_0(name, input, regexp) {
  var __v_6 = input.match(regexp);
 RegExp["$&"], name + "-$&";
}
__v_7 = "Argle bargle glop glyf!";
"Nonglobal-ignore-lastIndex"["A"], [], 1;
__v_11 = /()(.)(.)(.)(.)(.)(.)(.)(.)(.)/;
__v_4 = /\w+/g;
__f_0("Global-ignore-lastIndex", __v_7, __v_4, [], []);


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: msrchandra@chromium.org
Labels: Test-Predator-Wrong
Owner: jkummerow@chromium.org
Status: Assigned (was: Untriaged)
Find it did not provide any possible suspects.
Assigning to the concern owner from CL --
https://chromium.googlesource.com/v8/v8/+log/d1f347fa54ad962c1d109be0e194ff85784137da..af51befe694fe039db3554d4b9165f7d6baceb77?pretty=fuller


@jkummerow -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.
Project Member

Comment 2 by ClusterFuzz, Jan 13 2017

ClusterFuzz has detected this issue as fixed in range 42270:42271.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6098341713936384

Fuzzer: mbarbella_js_mutation
Job Type: linux_asan_d8_v8_mipsel_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  index >= 0 && index < length() in objects-inl.h
  
Sanitizer: address (ASAN)

Regressed: V8: r42167:42168
Fixed: V8: r42270:42271

Minimized Testcase (0.35 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97QwuwoTx23eYEJeH371PlQ9zQa1YxB-jFmW1X5JRJ32hmUs68oMlFzrf_cIspE0k-WIPZCAwTwQlMmWaqI-AkvTvTP-eIZ8HiZXmNsXE6DVh30rUKeWF3bFAouMyauE8K66O3osmqzTp1py8KwGbB2KEtP_EnUKLd_ed9Mvyn1i384MXgmnHKkTc-rEvLmwEH8_k79NnaDc4gN22sX_veMLFKasD_SeD5aw03f2Z6VK_id6W9ju9mSjzWL4MzjjsD5TgvUeV2jK94f9TQ_UTrXNcVPk7Yjk-3ygS4kYSFfKROKBs89BzAZG3F9dklj-hZ29IbAIb6I9V5pqu8Nm0Cc9gti7uF8A49Lwb485Ib4KTDIILc6IuHaOJZu8yqsDVsS5zmwQWFyuwmEgwu5FFn9dyHWIg?testcase_id=6098341713936384
var __v_8 = {};
var __v_10 = {};
var __v_11 = {};
var __v_12 = {};
function __f_0(name, input, regexp) {
  var __v_6 = input.match(regexp);
 RegExp["$&"], name + "-$&";
}
__v_7 = "Argle bargle glop glyf!";
"Nonglobal-ignore-lastIndex"["A"], [], 1;
__v_11 = /()(.)(.)(.)(.)(.)(.)(.)(.)(.)/;
__v_4 = /\w+/g;
__f_0("Global-ignore-lastIndex", __v_7, __v_4, [], []);


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Jan 13 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6098341713936384 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Mergedinto: 679735
Status: Duplicate (was: Verified)

Sign in to add a comment