New issue
Advanced search Search tips

Issue 856500 link

Starred by 2 users

Issue metadata

Status: Duplicate
Owner:
Closed: Jul 2
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security

Blocking:
issue v8:7853



Sign in to add a comment

CHECK failure: !v8::internal::FLAG_enable_slow_asserts || (object->IsSmi()) in objects-inl.h

Project Member Reported by ClusterFuzz, Jun 26 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6307002863845376

Fuzzer: ochang_js_fuzzer
Job Type: linux_d8_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  !v8::internal::FLAG_enable_slow_asserts || (object->IsSmi()) in objects-inl.h
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_d8_dbg&range=53905:53906

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6307002863845376

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jun 26 2018

Labels: Test-Predator-Auto-Owner
Owner: machenb...@chromium.org
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/v8/v8/+/17693fea1a4d834f883e3bb410cb40f419c3201b (Reland "[test] Initialize slow-dcheck runtime flag with compile time value").

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label. If you aren't the correct owner for this issue, please unassign yourself as soon as possible so it can be re-triaged.
Blocking: v8:7853
Cc: jgruber@chromium.org
Owner: mstarzinger@chromium.org
To clusterfuzz sheriff...
Cc: machenb...@chromium.org
Project Member

Comment 4 by sheriffbot@chromium.org, Jun 26 2018

Labels: Pri-1
Labels: Security_Impact-Stable M-67
Unsure if this impacts stable or caused due to recent enabling of slow assert, please adjust impact and milestone labels if needed.
Reduced repro ...

let a = [3.34];
function f() {}
a.shift();
f(...a);
Cc: mstarzinger@chromium.org
Owner: cbruni@chromium.org
Caused by the following, crashes even before this change, but differently ...

commit cb29d62068003e5138e957f3232872f7dfc33961
Author: Camillo Bruni <cbruni@chromium.org>
Date:   Wed Jun 6 11:42:25 2018 +0200

    [CSA] Fix assertion in CallOrConstructDoubleVarargs with empty FixedArray
    
    Bug:  chromium:850005 
    Change-Id: I287a274b86941e7d29705a24e479e4a02ecdfb07
    Reviewed-on: https://chromium-review.googlesource.com/1088608
    Reviewed-by: Jakob Gruber <jgruber@chromium.org>
    Commit-Queue: Camillo Bruni <cbruni@chromium.org>
    Cr-Commit-Position: refs/heads/master@{#53546}
Status: Started (was: Assigned)
I think jkummerow@ fixed this recently by fixing the asserts.
Will check.
Mergedinto: 856095
Status: Duplicate (was: Started)
Confirmed that jakob's CL fixes the failing check.
Project Member

Comment 10 by ClusterFuzz, Jul 3

ClusterFuzz has detected this issue as fixed in range 54148:54149.

Detailed report: https://clusterfuzz.com/testcase?key=6307002863845376

Fuzzer: ochang_js_fuzzer
Job Type: linux_d8_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  !v8::internal::FLAG_enable_slow_asserts || (object->IsSmi()) in objects-inl.h
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_d8_dbg&range=53905:53906
Fixed: https://clusterfuzz.com/revisions?job=linux_d8_dbg&range=54148:54149

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6307002863845376

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 8

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment