CHECK failure: actual_unused_property_fields > map()->UnusedPropertyFields() in objects-debug.c |
||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5384147026837504 Fuzzer: inferno_js_fuzzer Job Type: windows_asan_d8_dbg Platform Id: windows Crash Type: CHECK failure Crash Address: Crash State: actual_unused_property_fields > map()->UnusedPropertyFields() in objects-debug.c v8::platform::PrintStackTrace v8::internal::JSObject::JSObjectVerify Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_d8_dbg&range=49525:49526 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5384147026837504 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Nov 29 2017
,
Nov 29 2017
Bisect is wrong, the repro is flaky. Assigning to jarin@ who is currently working on a fix for this.
,
Nov 29 2017
Has been happening for a while. Not security relevant in release mode.
,
Dec 7 2017
,
Apr 11 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by ClusterFuzz
, Nov 29 2017Owner: jgruber@chromium.org
Status: Assigned (was: Untriaged)