Issue metadata
Sign in to add a comment
|
DCHECK failure in !dictionary->requires_slow_elements() in elements.cc |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5035834538196992 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: DCHECK failure Crash Address: Crash State: !dictionary->requires_slow_elements() in elements.cc FillImpl v8::internal::ElementsAccessorBase<v8::internal::DictionaryElementsAccessor, v8: Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_dbg&range=54521:54522 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5035834538196992 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Jul 19
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/4a6a631b5db32fb256bf5cd80b4adaff0ca57124 commit 4a6a631b5db32fb256bf5cd80b4adaff0ca57124 Author: Simon Zünd <szuend@google.com> Date: Thu Jul 19 06:53:11 2018 [array] Use Array.p.fill baseline version if object is non-extensible This CL fixes a bug where a fast-path was used on non-extensible objects. R=jgruber@chromium.org Bug: chromium:865264 , chromium:865285 Change-Id: Ie14c95b383a65576799c71576a5c0f9f8e1c29ca Reviewed-on: https://chromium-review.googlesource.com/1142766 Reviewed-by: Jakob Gruber <jgruber@chromium.org> Commit-Queue: Simon Zünd <szuend@google.com> Cr-Commit-Position: refs/heads/master@{#54539} [modify] https://crrev.com/4a6a631b5db32fb256bf5cd80b4adaff0ca57124/src/builtins/builtins-array.cc [modify] https://crrev.com/4a6a631b5db32fb256bf5cd80b4adaff0ca57124/test/mjsunit/es6/array-fill.js
,
Jul 19
,
Jul 19
ClusterFuzz has detected this issue as fixed in range 54538:54539. Detailed report: https://clusterfuzz.com/testcase?key=5035834538196992 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: DCHECK failure Crash Address: Crash State: !dictionary->requires_slow_elements() in elements.cc FillImpl v8::internal::ElementsAccessorBase<v8::internal::DictionaryElementsAccessor, v8: Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_dbg&range=54521:54522 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_d8_dbg&range=54538:54539 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5035834538196992 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 19
,
Jul 19
ClusterFuzz testcase 5035834538196992 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jul 19
Check if this fix needs to be back-merged into 6.9.
,
Jul 19
,
Jul 25
The NextAction date has arrived: 2018-07-25
,
Jul 25
Back-merging the fix is not needed since the original CL is not in 69: https://chromiumdash.appspot.com/commit/eeb583d8b89f954efd94ab884b4207187e5b9cc7
,
Jul 28
,
Jul 30
,
Jul 31
,
Oct 25
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Jul 19Owner: szuend@google.com
Status: Assigned (was: Untriaged)