V8 correctness failure in configs: x64,ignition:x64,slow_path |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4942775135764480 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,slow_path sources: 7dc Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=55575:55576 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4942775135764480 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Sep 10
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/e365bc2dcbf3b68bd4723cebe9842a8e646511ef commit e365bc2dcbf3b68bd4723cebe9842a8e646511ef Author: Simon Zünd <szuend@google.com> Date: Mon Sep 10 09:50:52 2018 [array] Consistently throw TypeError for zero-length arrays This CL fixes a bug that allowed calls to Array.p.shift on zero-length arrays where the 'length' is read-only without throwing a TypeError. R=bmeurer@chromium.org, jgruber@chromium.org Bug: chromium:882233 Change-Id: Ib129ab4c4f4f233e7bb553effa77539badfbe26e Reviewed-on: https://chromium-review.googlesource.com/1215164 Reviewed-by: Jakob Gruber <jgruber@chromium.org> Reviewed-by: Benedikt Meurer <bmeurer@chromium.org> Commit-Queue: Simon Zünd <szuend@google.com> Cr-Commit-Position: refs/heads/master@{#55746} [modify] https://crrev.com/e365bc2dcbf3b68bd4723cebe9842a8e646511ef/src/builtins/builtins-array-gen.cc [add] https://crrev.com/e365bc2dcbf3b68bd4723cebe9842a8e646511ef/test/mjsunit/regress/regress-crbug-882233-1.js [add] https://crrev.com/e365bc2dcbf3b68bd4723cebe9842a8e646511ef/test/mjsunit/regress/regress-crbug-882233-2.js
,
Sep 10
,
Sep 11
ClusterFuzz has detected this issue as fixed in range 55745:55746. Detailed report: https://clusterfuzz.com/testcase?key=4942775135764480 Fuzzer: foozzie_js_mutation Job Type: v8_foozzie Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: configs: x64,ignition:x64,slow_path sources: 7dc Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=55575:55576 Fixed: https://clusterfuzz.com/revisions?job=v8_foozzie&range=55745:55746 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4942775135764480 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 11
ClusterFuzz testcase 4942775135764480 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by ClusterFuzz
, Sep 9Owner: szuend@google.com
Status: Assigned (was: Untriaged)