Mercurial > hg > openjdk > aarch64-port > nashorn
changeset 1375:02421b7112bb
8066214: Fuzzing bug: Object.prototype.toLocaleString(0)
Reviewed-by: attila, lagergren
author | hannesw |
---|---|
date | Wed, 03 Dec 2014 11:43:57 +0100 |
parents | e3af6a3cd761 |
children | 201b37681668 |
files | src/jdk/nashorn/internal/objects/NativeObject.java test/script/basic/JDK-8066214.js test/script/basic/JDK-8066214.js.EXPECTED |
diffstat | 3 files changed, 65 insertions(+), 1 deletions(-) [+] |
line wrap: on
line diff
--- a/src/jdk/nashorn/internal/objects/NativeObject.java Mon Dec 15 12:08:36 2014 +0100 +++ b/src/jdk/nashorn/internal/objects/NativeObject.java Wed Dec 03 11:43:57 2014 +0100 @@ -499,7 +499,7 @@ final Object obj = JSType.toScriptObject(self); if (obj instanceof ScriptObject) { final InvokeByName toStringInvoker = getTO_STRING(); - final ScriptObject sobj = (ScriptObject)self; + final ScriptObject sobj = (ScriptObject)obj; try { final Object toString = toStringInvoker.getGetter().invokeExact(sobj);
--- /dev/null Thu Jan 01 00:00:00 1970 +0000 +++ b/test/script/basic/JDK-8066214.js Wed Dec 03 11:43:57 2014 +0100 @@ -0,0 +1,49 @@ +/* + * Copyright (c) 2014, Oracle and/or its affiliates. All rights reserved. + * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. + * + * This code is free software; you can redistribute it and/or modify it + * under the terms of the GNU General Public License version 2 only, as + * published by the Free Software Foundation. + * + * This code is distributed in the hope that it will be useful, but WITHOUT + * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or + * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License + * version 2 for more details (a copy is included in the LICENSE file that + * accompanied this code). + * + * You should have received a copy of the GNU General Public License version + * 2 along with this work; if not, write to the Free Software Foundation, + * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. + * + * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA + * or visit www.oracle.com if you need additional information or have any + * questions. + */ + +/** + * JDK-8066214: Fuzzing bug: Object.prototype.toLocaleString(0) + * + * @test + * @run + */ + +function test(func) { + print(func.call(0)); + print(func.call("abc")); + print(func.call(true)); + try { + print(func.call(undefined)); + } catch (e) { + print(e); + } + try { + print(func.call(null)); + } catch (e) { + print(e); + } +} + +test(Object.prototype.toLocaleString); +test(Object.prototype.toString); +test(Object.prototype.valueOf);
--- /dev/null Thu Jan 01 00:00:00 1970 +0000 +++ b/test/script/basic/JDK-8066214.js.EXPECTED Wed Dec 03 11:43:57 2014 +0100 @@ -0,0 +1,15 @@ +0 +abc +true +TypeError: undefined is not an Object +TypeError: null is not an Object +[object Number] +[object String] +[object Boolean] +[object Undefined] +[object Null] +0 +abc +true +TypeError: undefined is not an Object +TypeError: null is not an Object