New issue
Advanced search Search tips

Issue 797758 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

ASSERT: failed: got "-NUMBER", expected "{"1.79769313486e+308":[object Object]}":

Project Member Reported by ClusterFuzz, Dec 27 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5839414348742656

Fuzzer: inferno_js_fuzzer
Job Type: linux_cfi_d8
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  failed: got "-NUMBER", expected "{"1.79769313486e+308":[object Object]}":
  
Sanitizer: cfi (CFI)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5839414348742656

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Dec 27 2017

Labels: Pri-1
Hmmm. This repros back to at least Chrome 63, and Clusterfuzz notes REGRESSION REVISION RANGE of V8: 0:47824. It returns the same results in Firefox and Edge, making me wonder whether this test case is really valid.
Cc: clemensh@chromium.org
Owner: mmoroz@chromium.org
Status: Assigned (was: Untriaged)
I agree. I don't even see a failure here. The script throws a TypeError, that's all.
Assigning to Max to clarify why this was even reported by Clusterfuzz. Maybe just because of the string "Assertion failed"?

Please set back to Untriaged to get it back to the queue, or set to WontFix if this is indeed an invalid report.

Comment 4 by mmoroz@google.com, Dec 27 2017

Cc: -clemensh@chromium.org mmoroz@chromium.org
Owner: clemensh@chromium.org
Right, "Assertion failed" is the root cause why this got reported. Feel free to WontFix.
Status: WontFix (was: Assigned)
Ok, thanks. Any chance to suppress such reports in the future? Maybe only match "Assertion failed" at the beginning of a line?

Comment 6 by mmoroz@google.com, Dec 27 2017

Cc: mbarbe...@chromium.org infe...@chromium.org
I don't think that beginning of a line would work :/ Also, it doesn't seem to happen often. At least I haven't seen such cases before. If I'm wrong and that happens quite often, it would be great to see other examples and then figure out a good soluion.
Project Member

Comment 7 by ClusterFuzz, Jan 3 2018

Labels: Needs-Feedback
ClusterFuzz testcase 5839414348742656 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
Labels: ClusterFuzz-Ignore
Project Member

Comment 9 by sheriffbot@chromium.org, Apr 5 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment