Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Segmentation Fault in release. Assertion 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed on debug. #5104

Open
anbu1024 opened this issue Oct 18, 2023 · 0 comments
Labels
bug Undesired behaviour fuzzing Related to fuzz testing of the engine parser Related to the JavaScript parser

Comments

@anbu1024
Copy link

jerryScript version 3.0.0:
commit 05dbbd1

Build platform:
Ubuntu 20.04

Build cmd:

python tools/build.py --debug --profile=es.next --lto=off --compile-flag=-D_POSIX_C_SOURCE=200809 --compile-flag=-Wno-strict-prototypes --stack-limit=15

Test case

class Foo {
    valueOf(m, n) {
        var a;
        
        try { a = this.valueOf(); } catch (e) {}
        
        var b = `
            class Bar extends m {
                constructor(a21, a22) {
                }
                static {
                    for (let i25 = 0; i25 < 5;) {
                    }
                }
                /*
                constructor(a31) {
                    /0()*/;
                    isNaN(a);
                }
                */
            }
        `;
        eval(b, eval, this, a);
    }
}

var c = new Foo();

c.valueOf();

Error message:

SEGV on ASAN version

AddressSanitizer:DEADLYSIGNAL
=================================================================
==505902==ERROR: AddressSanitizer: SEGV on unknown address 0x000000002cee (pc 0x55ca4212e04b bp 0x7ffc2cef5740 sp 0x7ffc2cef56a0 T0)
==505902==The signal is caused by a READ memory access.

Aborted with assertion error in debug version:

ICE: Assertion 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at jerry-core/parser/js/js-parser.c(parser_parse_function_arguments):1587.
Error: JERRY_FATAL_FAILED_ASSERTION
Aborted (core dumped)
@LaszloLango LaszloLango added bug Undesired behaviour parser Related to the JavaScript parser fuzzing Related to fuzz testing of the engine labels Nov 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Undesired behaviour fuzzing Related to fuzz testing of the engine parser Related to the JavaScript parser
Projects
None yet
Development

No branches or pull requests

2 participants