New issue
Advanced search Search tips

Issue 686409 link

Starred by 2 users

Issue metadata

Status: Verified
Owner: ----
Closed: Feb 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

map()->unused_property_fields() == actual_unused_property_fields - JSObject::kFi

Project Member Reported by ClusterFuzz, Jan 28 2017

Issue description

Project Member

Comment 1 by ClusterFuzz, Feb 1 2017

ClusterFuzz has detected this issue as fixed in range 447218:447232.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5709845694251008

Fuzzer: lcamtuf_cross_fuzz
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: CHECK failure
Crash Address: 
Crash State:
  map()->unused_property_fields() == actual_unused_property_fields - JSObject::kFi
  
Sanitizer: address (ASAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=446618:446638
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=447218:447232

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97WnbN1-ReY_xBczzOajQTfcAw35XN6C1KLKc08SOSXYEFENy2ASvyaE2ZrCos4h6iv0HvvlbYpyXQEpLxGlp8Zg3OxKDmMB76IGV9x2Fcaiitzyw94_D7hEI4-9u9p3uTsash0ZsAwIT_ntLKQn4kkkt-OU3pmePSauPLBcgvT2LgTNW6xgZgVun6qM5WoBhZowFGg9S9km1bbPa_Iy4cH9Z2QvyJUJ0yWSeYtuMqOihsqGsZslXgsAofd9Au_ZONK9xICfGgB9bDfCJpvKiUEMpDtZVGZ1ZCE1baGKdZxNaJva-Od2x39KNeHXT-GdfOYT9GIqIfOsLmbwqUnx3fzfz7uTN2XG_6X5HCd_xTRl5-s1j8?testcase_id=5709845694251008


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 2 by ClusterFuzz, Feb 1 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Untriaged)
ClusterFuzz testcase 5709845694251008 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment