Ill in v8::internal::RemoveArrayHolesGeneric |
||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6275016120074240 Fuzzer: ochang_js_fuzzer Job Type: linux_ubsan_vptr_d8 Platform Id: linux Crash Type: Ill Crash Address: 0x55bb5de10f4e Crash State: v8::internal::RemoveArrayHolesGeneric RemoveArrayHoles __RT_impl_Runtime_PrepareElementsForSort Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_d8&range=53198:53199 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6275016120074240 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Jul 23
,
Jul 23
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/bc017d81d6e3d215a3f7d53374561f3dfbadfb8f commit bc017d81d6e3d215a3f7d53374561f3dfbadfb8f Author: Simon Zünd <szuend@google.com> Date: Mon Jul 23 09:00:06 2018 [array] Change array indices handling for proxies in sort preprocessing For JSProxies we filled a FixedArray with the numbers from 0 to length - 1. Because all indices were assumed to be Smis, large array indices on Proxies were not handled correctly. R=jgruber@chromium.org Bug: chromium:866314 Change-Id: I6a792e800f31617a6092b219ec82b0e05a83bf7b Reviewed-on: https://chromium-review.googlesource.com/1146562 Reviewed-by: Jakob Gruber <jgruber@chromium.org> Commit-Queue: Simon Zünd <szuend@google.com> Cr-Commit-Position: refs/heads/master@{#54603} [modify] https://crrev.com/bc017d81d6e3d215a3f7d53374561f3dfbadfb8f/src/runtime/runtime-array.cc
,
Jul 23
,
Jul 24
ClusterFuzz has detected this issue as fixed in range 54602:54603. Detailed report: https://clusterfuzz.com/testcase?key=6275016120074240 Fuzzer: ochang_js_fuzzer Job Type: linux_ubsan_vptr_d8 Platform Id: linux Crash Type: Ill Crash Address: 0x55bb5de10f4e Crash State: v8::internal::RemoveArrayHolesGeneric RemoveArrayHoles __RT_impl_Runtime_PrepareElementsForSort Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_d8&range=53198:53199 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_d8&range=54602:54603 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6275016120074240 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 24
ClusterFuzz testcase 6275016120074240 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by ClusterFuzz
, Jul 22Owner: szuend@google.com
Status: Assigned (was: Untriaged)