chakra-core/ChakraCore

Assertion failure in JavascriptArray.cpp

Open

#6,770 opened on Dec 24, 2021

View on GitHub
 (7 comments) (0 reactions) (0 assignees)JavaScript (9,000 stars) (1,374 forks)batch import
Buggood first issue

Description

the following poc cause a assertion failure in "debug" build on ubuntu.

function opt(){
	const v2 = [-1000000000.0];
	v2.length = 4294967295;
	const v3 = v2.copyWithin();
	return v3;
}


for(let i=0;i<0x200;i++){
	opt(false);
}

Contributor guide