New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 789765 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 789393
Owner:
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac , Fuchsia
Pri: 1
Type: Bug-Security



Sign in to add a comment

CHECK failure: !v8::internal::FLAG_enable_slow_asserts || (len < LengthField::kMax) in objects-

Project Member Reported by ClusterFuzz, Nov 30 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5067316416217088

Job Type: linux_asan_d8_dbg
Crash Type: CHECK failure
Crash Address: 
Crash State:
  !v8::internal::FLAG_enable_slow_asserts || (len < LengthField::kMax) in objects-
  v8::internal::PropertyArray::initialize_length
  v8::internal::Heap::AllocatePropertyArray
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_dbg&range=46849:46850

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5067316416217088

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Nov 30 2017

Components: Blink>JavaScript>GC
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Nov 30 2017

Labels: Test-Predator-Auto-Owner
Owner: gsat...@chromium.org
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/v8/v8/+/fe18ad65806cc17f669575aeec3defb368bfff6c (Reland "[runtime] Load only 10 bits as PropertyArray length").

If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.

Comment 3 by raymes@chromium.org, Nov 30 2017

Labels: Security_Impact-Stable M-64
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 30 2017

Labels: Pri-1
Project Member

Comment 5 by ClusterFuzz, Dec 14 2017

ClusterFuzz has detected this issue as fixed in range 50085:50086.

Detailed report: https://clusterfuzz.com/testcase?key=5067316416217088

Job Type: linux_asan_d8_dbg
Crash Type: CHECK failure
Crash Address: 
Crash State:
  !v8::internal::FLAG_enable_slow_asserts || (len < LengthField::kMax) in objects-
  v8::internal::PropertyArray::initialize_length
  v8::internal::Heap::AllocatePropertyArray
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_dbg&range=46849:46850
Fixed: https://clusterfuzz.com/revisions?job=linux_asan_d8_dbg&range=50085:50086

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5067316416217088

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Dec 14 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5067316416217088 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 7 by sheriffbot@chromium.org, Dec 14 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 8 by sheriffbot@chromium.org, Dec 16 2017

Labels: Merge-Request-64
Project Member

Comment 9 by sheriffbot@chromium.org, Dec 16 2017

Labels: -Merge-Request-64 Hotlist-Merge-Review Merge-Review-64
This bug requires manual review: M64 has already been promoted to the beta branch, so this requires manual review
Please contact the milestone owner if you have questions.
Owners: cmasso@(Android), cmasso@(iOS), kbleicher@(ChromeOS), abdulsyed@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Can you please mark all OS's this impacts?
abdulsyed@ - good for 64 (for reference, I believe the fix to be merged is https://chromium.googlesource.com/v8/v8/+/3ecb047abae69064052f268896afd3fe0824e0ce)
gsathya@ - can you please confirm if this is well tested in Canary? And overall safe to merge in M64?
Labels: OS-Android OS-Chrome OS-Fuchsia OS-Linux OS-Mac OS-Windows
Yes -- looks like fix went into 65.0.3295.0 which was released on Dec 16 https://chromiumdash-staging.googleplex.com/commit/3ecb047abae69064052f268896afd3fe0824e0ce


Mergedinto: 789393
Status: Duplicate (was: Verified)
Labels: -Merge-Review-64 Merge-Approved-64
Approving merge for M64. Branch:3282
can you confirm if this has been merged yet?
Please merge the approved cl(s) to M64 release branch 3282 as soon as possible.
Labels: -Merge-Approved-64 Merge-Merged
Project Member

Comment 21 by sheriffbot@chromium.org, Mar 29 2018

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment