Bug 5176 - run-webkit-tests --guard crashes on TOT
Summary: run-webkit-tests --guard crashes on TOT
Status: RESOLVED FIXED
Alias: None
Product: WebKit
Classification: Unclassified
Component: New Bugs (show other bugs)
Version: 420+
Hardware: Mac OS X 10.4
: P1 Normal
Assignee: Eric Seidel (no email)
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-09-28 17:59 PDT by Eric Seidel (no email)
Modified: 2005-10-02 14:55 PDT (History)
1 user (show)

See Also:


Attachments
suggested patch (815 bytes, patch)
2005-09-29 11:22 PDT, mitz
no flags Details | Formatted Diff | Diff
updated patch (1.48 KB, patch)
2005-09-29 14:14 PDT, mitz
darin: review+
Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Eric Seidel (no email) 2005-09-28 17:59:45 PDT
run-webkit-tests --svg --guard crashes on TOT

I expect this is related to the PCRE 6.1 changes.

Date/Time:      2005-09-28 17:58:10.141 -0700
OS Version:     10.4.2 (Build 8B1071)
Report Version: 4

Command: DumpKCanvasTree
Path:    /Volumes/Stuff/Projects/build/Development/DumpKCanvasTree
Parent:  perl [2516]

Version: ??? (???)

PID:    2582
Thread: 0

Exception:  EXC_BAD_ACCESS (0x0001)
Codes:      KERN_PROTECTION_FAILURE (0x0002) at 0x186ed000

Thread 0 Crashed:
0   com.apple.JavaScriptCore 	0x00284e38 match + 15812 (pcre_exec.c:1852)
1   com.apple.JavaScriptCore 	0x00281578 match + 1284 (pcre_exec.c:627)
2   com.apple.JavaScriptCore 	0x0028248c match + 5144 (pcre_exec.c:1005)
3   com.apple.JavaScriptCore 	0x00288b10 match + 31388 (pcre_exec.c:3128)
4   com.apple.JavaScriptCore 	0x002854fc match + 17544 (pcre_exec.c:1974)
5   com.apple.JavaScriptCore 	0x00288b10 match + 31388 (pcre_exec.c:3128)
6   com.apple.JavaScriptCore 	0x002854fc match + 17544 (pcre_exec.c:1974)
7   com.apple.JavaScriptCore 	0x002812e4 match + 624 (pcre_exec.c:597)
8   com.apple.JavaScriptCore 	0x00281578 match + 1284 (pcre_exec.c:627)
9   com.apple.JavaScriptCore 	0x00289ae0 kjs_pcre_exec + 2700 (pcre_exec.c:3693)
10  com.apple.WebCore        	0x0106b0a8 QRegExp::match(QString const&, int, int*) const + 276 
(KWQRegExp.mm:159)
11  com.apple.WebCore        	0x0106b2ec QRegExp::search(QString const&, int) const + 88 
(KWQRegExp.mm:184)
12  com.apple.WebCore        	0x013e64c8 KSVG::SVGTransformableImpl::parseTransformAttribute
(KSVG::SVGTransformListImpl*, KDOM::DOMStringImpl*) + 836 (SVGTransformableImpl.cpp:179)
13  com.apple.WebCore        	0x013e7088 KSVG::SVGTransformableImpl::parseAttribute
(KDOM::AttributeImpl*) + 156 (SVGTransformableImpl.cpp:144)
14  com.apple.WebCore        	0x013b1980 KSVG::SVGGElementImpl::parseAttribute
(KDOM::AttributeImpl*) + 144 (SVGGElementImpl.cpp:45)
15  com.apple.WebCore        	0x0145a23c KDOM::NamedAttrMapImpl::setValue(unsigned, 
KDOM::DOMStringImpl*, KDOM::DOMStringImpl*, KDOM::DOMStringImpl*, bool, bool) + 1408 
(NamedAttrMapImpl.cpp:333)
16  com.apple.WebCore        	0x01453dc0 KDOM::ElementImpl::setAttributeNS
(KDOM::DOMStringImpl*, KDOM::DOMStringImpl*, KDOM::DOMStringImpl*) + 756 (ElementImpl.cpp:
305)
17  com.apple.WebCore        	0x0147253c KDOM::DocumentBuilder::startAttributeNS
(KDOM::DOMString const&, KDOM::DOMString const&, KDOM::DOMString const&) + 348 
(KDOMDocumentBuilder.cpp:226)
18  com.apple.WebCore        	0x013ef078 sax_start_element_ns(void*, unsigned char const*, 
unsigned char const*, unsigned char const*, int, unsigned char const**, int, int, unsigned char const**) 
+ 3388 (LibXMLParser.cpp:189)
19  libxml2.2.dylib          	0x92c9eb20 xmlParseStartTag + 6896
20  libxml2.2.dylib          	0x92c7cc20 xmlParseChunk + 1824
21  com.apple.WebCore        	0x013f157c KDOM::LibXMLParser::doOneShotParse(char const*, 
unsigned) + 284 (LibXMLParser.cpp:531)
22  com.apple.WebCore        	0x014af2d8 -[DrawDocument initWithSVGData:] + 600 
(DrawDocument.mm:197)
23  com.apple.WebCore        	0x014af644 -[DrawDocument initWithContentsOfFile:] + 216 
(DrawDocument.mm:222)
24  DumpKCanvasTree.ob       	0x000d7d04 dumpRenderTree + 316 (DumpKCanvasTree.m:120)
25  DumpKCanvasTree.ob       	0x000d7ad8 main + 928 (DumpKCanvasTree.m:96)
26  DumpKCanvasTree          	0x00002520 start + 408
27  DumpKCanvasTree          	0x000023c4 start + 60

Thread 0 crashed with PPC Thread State 64:
  srr0: 0x0000000000284e38 srr1: 0x100000000200f030                        vrsave: 
0x0000000000000000
    cr: 0x22000448          xer: 0x0000000000000000   lr: 0x000000000028108c  ctr: 
0x0000000000284d10
    r0: 0x0000000000000040   r1: 0x00000000bfffca60   r2: 0x0000000000000065   r3: 
0x00000000186ed000
    r4: 0x00000000186fafea   r5: 0x0000000000000002   r6: 0x00000000bfffe3b8   r7: 
0x0000000000000001
    r8: 0x00000000bfffcef4   r9: 0x0000000000000065  r10: 0x00000000186fafec  r11: 
0x00000000186ed000
   r12: 0x0000000000289054  r13: 0x00000000bffff20c  r14: 0x00000000bffff208  r15: 
0x00000000bffff1f8
   r16: 0x0000000000000000  r17: 0x00000000000030d3  r18: 0x0000000000000001  r19: 
0x0000000000000037
   r20: 0x0000000000000000  r21: 0x000000000f104f28  r22: 0x0000000000000000  r23: 
0x0000000000000005
   r24: 0x000000000edbcd1f  r25: 0x0000000000000005  r26: 0x000000000f104f24  r27: 
0x000000000f104f38
   r28: 0x000000000eda6e48  r29: 0x000000000edbcc5b  r30: 0x00000000bfffca60  r31: 
0x000000000028108c

Binary Images Description:
    0x1000 -     0xffff DumpKCanvasTree 	/Volumes/Stuff/Projects/build/Development/
DumpKCanvasTree
   0xd6000 -    0xd8fff DumpKCanvasTree.ob 	/Volumes/Stuff/Projects/build/
DumpKCanvasTree.build/Development/DumpKCanvasTree.build/Objects-normal/ppc/
DumpKCanvasTree.ob
  0x205000 -   0x2b0fff com.apple.JavaScriptCore 420+	/Volumes/Stuff/Projects/build/Development/
JavaScriptCore.framework/Versions/A/JavaScriptCore
 0x1008000 -  0x189bfff com.apple.WebCore 420+	/Volumes/Stuff/Projects/build/Development/
WebCore.framework/Versions/A/WebCore
0x8fe00000 - 0x8fe55fff dyld 44.5	/usr/lib/dyld
0x90000000 - 0x901b6fff libSystem.B.dylib 	/usr/lib/libSystem.B.dylib
0x9020e000 - 0x90213fff libmathCommon.A.dylib 	/usr/lib/system/libmathCommon.A.dylib
0x90215000 - 0x90257fff com.apple.CoreText 1.1.0 (???)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/CoreText.framework/Versions/A/CoreText
0x9027f000 - 0x9035efff ATS 	/System/Library/Frameworks/ApplicationServices.framework/Versions/
A/Frameworks/ATS.framework/Versions/A/ATS
0x90387000 - 0x9072ffff com.apple.CoreGraphics 1.258.5 (???)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
CoreGraphics.framework/Versions/A/CoreGraphics
0x907be000 - 0x90894fff com.apple.CoreFoundation 6.4.4 (368.16)
	/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
0x908db000 - 0x908dbfff com.apple.CoreServices 10.4 (???)	/System/Library/Frameworks/
CoreServices.framework/Versions/A/CoreServices
0x908dd000 - 0x909e3fff libicucore.A.dylib 	/usr/lib/libicucore.A.dylib
0x90a3a000 - 0x90abefff libobjc.A.dylib 	/usr/lib/libobjc.A.dylib
0x90ae7000 - 0x90b57fff libstdc++.6.dylib 	/usr/lib/libstdc++.6.dylib
0x90bca000 - 0x90bd5fff libgcc_s.1.dylib 	/usr/lib/libgcc_s.1.dylib
0x90bda000 - 0x90bfcfff libmx.A.dylib 	/usr/lib/libmx.A.dylib
0x90c02000 - 0x90c73fff IOKit 	/System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
0x90c89000 - 0x90c9cfff libauto.dylib 	/usr/lib/libauto.dylib
0x90ca2000 - 0x90f69fff com.apple.CoreServices.CarbonCore 10.4.3 (659)
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
CarbonCore.framework/Versions/A/CarbonCore
0x90fc5000 - 0x9103efff com.apple.CoreServices.OSServices 4.1
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
OSServices.framework/Versions/A/OSServices
0x91082000 - 0x910c1fff com.apple.CFNetwork 10.4.3 (129.2)
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
CFNetwork.framework/Versions/A/CFNetwork
0x910d5000 - 0x910e8fff com.apple.WebServices 1.1.2 (1.1.0)
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
WebServicesCore.framework/Versions/A/WebServicesCore
0x910f4000 - 0x9117bfff com.apple.SearchKit 1.0.4	/System/Library/Frameworks/
CoreServices.framework/Versions/A/Frameworks/SearchKit.framework/Versions/A/SearchKit
0x911b1000 - 0x911d1fff com.apple.Metadata 10.4.3 (121.16)
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
Metadata.framework/Versions/A/Metadata
0x911de000 - 0x911ecfff libz.1.dylib 	/usr/lib/libz.1.dylib
0x911ef000 - 0x913c6fff com.apple.security 4.2.1 (24989)	/System/Library/Frameworks/
Security.framework/Versions/A/Security
0x914bc000 - 0x914c5fff com.apple.DiskArbitration 2.1	/System/Library/Frameworks/
DiskArbitration.framework/Versions/A/DiskArbitration
0x914cc000 - 0x914f4fff com.apple.SystemConfiguration 1.8.5
	/System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfiguration
0x91506000 - 0x9150efff libbsm.dylib 	/usr/lib/libbsm.dylib
0x91512000 - 0x91597fff com.apple.audio.CoreAudio 3.0.2	/System/Library/Frameworks/
CoreAudio.framework/Versions/A/CoreAudio
0x915e3000 - 0x915e3fff com.apple.ApplicationServices 10.4 (???)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/ApplicationServices
0x915e5000 - 0x91617fff com.apple.AE 1.5 (297)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/AE.framework/Versions/A/AE
0x9162d000 - 0x916fffff com.apple.ColorSync 4.4.3	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/ColorSync.framework/Versions/A/ColorSync
0x9173c000 - 0x917ccfff com.apple.print.framework.PrintCore 4.3 (172.2)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
PrintCore.framework/Versions/A/PrintCore
0x91808000 - 0x918bafff com.apple.QD 3.9.0 (???)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/QD.framework/Versions/A/QD
0x918ec000 - 0x91942fff com.apple.HIServices 1.5.1 (???)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/HIServices.framework/Versions/A/HIServices
0x91969000 - 0x91982fff com.apple.LangAnalysis 1.6.1	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/LangAnalysis.framework/Versions/A/
LangAnalysis
0x9198d000 - 0x919aafff com.apple.FindByContent 1.5	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/FindByContent.framework/Versions/A/
FindByContent
0x919b6000 - 0x919f1fff com.apple.LaunchServices 10.4.5 (167)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
LaunchServices.framework/Versions/A/LaunchServices
0x91a08000 - 0x91a15fff com.apple.speech.synthesis.framework 3.4
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
SpeechSynthesis.framework/Versions/A/SpeechSynthesis
0x91a1d000 - 0x91a4efff com.apple.ImageIO.framework 1.0.3
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
ImageIO.framework/Versions/A/ImageIO
0x91a61000 - 0x91b1dfff libcrypto.0.9.7.dylib 	/usr/lib/libcrypto.0.9.7.dylib
0x91b66000 - 0x91b7bfff libcups.2.dylib 	/usr/lib/libcups.2.dylib
0x91b80000 - 0x91b9dfff libJPEG.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libJPEG.dylib
0x91ba2000 - 0x91c00fff libJP2.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libJP2.dylib
0x91c10000 - 0x91c14fff libGIF.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libGIF.dylib
0x91c16000 - 0x91c49fff libRaw.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libRaw.dylib
0x91c4c000 - 0x91c90fff libTIFF.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libTIFF.dylib
0x91c96000 - 0x91cb0fff libPng.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libPng.dylib
0x91cb5000 - 0x91cb7fff libRadiance.dylib 	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/
libRadiance.dylib
0x91cb9000 - 0x91cb9fff com.apple.Accelerate 1.2.1 (Accelerate 1.2.1)
	/System/Library/Frameworks/Accelerate.framework/Versions/A/Accelerate
0x91cbb000 - 0x91d92fff com.apple.vImage 2.2	/System/Library/Frameworks/
Accelerate.framework/Versions/A/Frameworks/vImage.framework/Versions/A/vImage
0x91d9a000 - 0x91db9fff com.apple.Accelerate.vecLib 3.2.1 (vecLib 3.2.1)
	/System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/
Versions/A/vecLib
0x91e25000 - 0x91e8efff libvMisc.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libvMisc.dylib
0x91e98000 - 0x91f2efff libvDSP.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libvDSP.dylib
0x91f48000 - 0x924d1fff libBLAS.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libBLAS.dylib
0x92504000 - 0x92831fff libLAPACK.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libLAPACK.dylib
0x92861000 - 0x928f3fff com.apple.DesktopServices 1.3.1	/System/Library/PrivateFrameworks/
DesktopServicesPriv.framework/Versions/A/DesktopServicesPriv
0x92932000 - 0x92b61fff com.apple.Foundation 6.4.2 (567.16)
	/System/Library/Frameworks/Foundation.framework/Versions/C/Foundation
0x92c76000 - 0x92d62fff libxml2.2.dylib 	/usr/lib/libxml2.2.dylib
0x92d81000 - 0x92e70fff libiconv.2.dylib 	/usr/lib/libiconv.2.dylib
0x92e81000 - 0x92ea0fff libGL.dylib 	/System/Library/Frameworks/OpenGL.framework/Versions/
A/Libraries/libGL.dylib
0x92eab000 - 0x92f01fff libGLU.dylib 	/System/Library/Frameworks/OpenGL.framework/Versions/
A/Libraries/libGLU.dylib
0x92f19000 - 0x92f19fff com.apple.Carbon 10.4 (???)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Carbon
0x92f1b000 - 0x92f2cfff com.apple.ImageCapture 3.0.3	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/ImageCapture.framework/Versions/A/ImageCapture
0x92f3c000 - 0x92f46fff com.apple.speech.recognition.framework 3.5
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
SpeechRecognition.framework/Versions/A/SpeechRecognition
0x92f4e000 - 0x92f56fff com.apple.securityhi 2.0.1 (24742)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/SecurityHI.framework/Versions/A/SecurityHI
0x92f5d000 - 0x92fe8fff com.apple.ink.framework 101.2.1 (70)
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Ink.framework/
Versions/A/Ink
0x92ffd000 - 0x93001fff com.apple.help 1.0.3 (32)	/System/Library/Frameworks/Carbon.framework/
Versions/A/Frameworks/Help.framework/Versions/A/Help
0x93005000 - 0x93026fff com.apple.openscripting 1.2.2 (???)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/OpenScripting.framework/Versions/A/OpenScripting
0x93039000 - 0x93042fff com.apple.print.framework.Print 5.0 (189)
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Print.framework/
Versions/A/Print
0x93049000 - 0x930aefff com.apple.htmlrendering 66.1 (1.1.3)
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
HTMLRendering.framework/Versions/A/HTMLRendering
0x930d4000 - 0x9311afff com.apple.NavigationServices 3.4.2	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/NavigationServices.framework/Versions/A/
NavigationServices
0x9313b000 - 0x9314bfff com.apple.audio.SoundManager 3.9.1
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
CarbonSound.framework/Versions/A/CarbonSound
0x93154000 - 0x9315afff com.apple.CommonPanels 1.2.2 (73)
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
CommonPanels.framework/Versions/A/CommonPanels
0x93160000 - 0x93460fff com.apple.HIToolbox 1.4.5 (???)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/HIToolbox.framework/Versions/A/HIToolbox
0x93588000 - 0x93594fff com.apple.opengl 1.4.3	/System/Library/Frameworks/OpenGL.framework/
Versions/A/OpenGL
0x9361e000 - 0x9361efff com.apple.Cocoa 6.4 (???)	/System/Library/Frameworks/
Cocoa.framework/Versions/A/Cocoa
0x93620000 - 0x93d3bfff com.apple.AppKit 6.4.3 (824.19)	/System/Library/Frameworks/
AppKit.framework/Versions/C/AppKit
0x940bc000 - 0x9412efff com.apple.CoreData 50 (76)	/System/Library/Frameworks/
CoreData.framework/Versions/A/CoreData
0x94167000 - 0x94240fff com.apple.audio.toolbox.AudioToolbox 1.4.2
	/System/Library/Frameworks/AudioToolbox.framework/Versions/A/AudioToolbox
0x94284000 - 0x94284fff com.apple.audio.units.AudioUnit 1.4.2
	/System/Library/Frameworks/AudioUnit.framework/Versions/A/AudioUnit
0x94286000 - 0x94427fff com.apple.QuartzCore 1.4.4	/System/Library/Frameworks/
QuartzCore.framework/Versions/A/QuartzCore
0x9446e000 - 0x944acfff libsqlite3.0.dylib 	/usr/lib/libsqlite3.0.dylib
0x944b4000 - 0x94504fff libGLImage.dylib 	/System/Library/Frameworks/OpenGL.framework/
Versions/A/Libraries/libGLImage.dylib
0x946a0000 - 0x946acfff libCSync.A.dylib 	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/
Resources/libCSync.A.dylib
0x946b2000 - 0x946d5fff libPDFRIP.A.dylib 	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/
Resources/libPDFRIP.A.dylib
0x946fa000 - 0x94713fff libRIP.A.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libRIP.A.dylib
0x95c66000 - 0x95c8efff libxslt.1.dylib 	/usr/lib/libxslt.1.dylib
0x965d6000 - 0x965d7fff com.apple.zerolink 1.2 (3)	/System/Library/PrivateFrameworks/
ZeroLink.framework/Versions/A/ZeroLink
0x9bd5f000 - 0x9bd61fff libgmalloc.dylib 	/usr/lib/libgmalloc.dylib

Model: PowerMac7,2, BootROM 5.1.5f0, 2 processors, PowerPC 970  (2.2), 2 GHz, 1.5 GB
Graphics: ATI Radeon 9600 Pro, ATY,RV350, AGP, 64 MB
Memory Module: DIMM0/J11, 512 MB, DDR SDRAM, PC3200U-30330
Memory Module: DIMM1/J12, 512 MB, DDR SDRAM, PC3200U-30330
Memory Module: DIMM2/J13, 256 MB, DDR SDRAM, PC3200U-30330
Memory Module: DIMM3/J14, 256 MB, DDR SDRAM, PC3200U-30330
Modem: MicroDash, UCJ, V.92, 1.0F, APPLE VERSION 2.6.6
Network Service: Built-in Ethernet, Ethernet, en0
Serial ATA Device: ST3160023AS, 149.05 GB
Parallel ATA Device: PIONEER DVD-RW  DVR-106D, 1.03 GB
USB Device: Hub in Apple Pro Keyboard, Mitsumi Electric, Up to 12 Mb/sec, 500 mA
USB Device: Apple Optical USB Mouse, Mitsumi Electric, Up to 1.5 Mb/sec, 100 mA
USB Device: Apple Pro Keyboard, Mitsumi Electric, Up to 12 Mb/sec, 250 mA
Comment 1 Eric Seidel (no email) 2005-09-28 18:01:20 PDT
run-webkit-tests --svg --guard W3C-SVG-1.1/coords-trans-01-b.svg

is enough to reproduce.
Comment 2 Eric Seidel (no email) 2005-09-29 07:30:03 PDT
It turns out this is no SVG specific.  Normal WebCore TOT crashes too:

run-webkit-tests --guard apple-only/dig/DigEncode.html

I'm still trying to reproduce this with an open source test.

Date/Time:      2005-09-29 07:16:34.239 -0700
OS Version:     10.4.3 (Build 8F31)
Report Version: 3

Command: DumpRenderTree
Path:    /Volumes/Stuff/Projects/build/Development/DumpRenderTree
Parent:  perl [10794]

Version: ??? (???)

PID:    10818
Thread: 0

Exception:  EXC_BAD_ACCESS (0x0001)
Codes:      KERN_PROTECTION_FAILURE (0x0002) at 0xe6209000

Thread 0 Crashed:
0   com.apple.JavaScriptCore 	0x05d20f08 match + 15256 (pcre_exec.c:1812)
1   com.apple.JavaScriptCore 	0x05d1d874 match + 1284 (pcre_exec.c:627)
2   com.apple.JavaScriptCore 	0x05d25ddc kjs_pcre_exec + 2700 (pcre_exec.c:3693)
3   com.apple.JavaScriptCore 	0x05ce0f94 KJS::RegExp::match(KJS::UString const&, int, int*, int**) + 
432 (regexp.cpp:125)
4   com.apple.JavaScriptCore 	0x05ce2480 replace(KJS::ExecState*, KJS::UString const&, 
KJS::ValueImp*, KJS::ValueImp*) + 580 (string_object.cpp:291)
5   com.apple.JavaScriptCore 	0x05ce3f7c KJS::StringProtoFuncImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 3200 (string_object.cpp:513)
6   com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
7   com.apple.JavaScriptCore 	0x05cca568 KJS::FunctionCallDotNode::evaluate(KJS::ExecState*) + 904 
(nodes.cpp:641)
8   com.apple.JavaScriptCore 	0x05cd557c KJS::AssignResolveNode::evaluate(KJS::ExecState*) + 448 
(nodes.cpp:1302)
9   com.apple.JavaScriptCore 	0x05ccf0e0 KJS::ExprStatementNode::execute(KJS::ExecState*) + 220 
(nodes.cpp:1594)
10  com.apple.JavaScriptCore 	0x05cd4f78 KJS::SourceElementsNode::execute(KJS::ExecState*) + 280 
(nodes.cpp:2316)
11  com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
12  com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
13  com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
14  com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
15  com.apple.JavaScriptCore 	0x05cca148 KJS::FunctionCallBracketNode::evaluate(KJS::ExecState*) + 
1232 (nodes.cpp:602)
16  com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
17  com.apple.JavaScriptCore 	0x05ccded4 KJS::StatListNode::execute(KJS::ExecState*) + 104 
(nodes.cpp:1423)
18  com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
19  com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
20  com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
21  com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
22  com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
23  com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
24  com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
25  com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
26  com.apple.JavaScriptCore 	0x05cca568 KJS::FunctionCallDotNode::evaluate(KJS::ExecState*) + 904 
(nodes.cpp:641)
27  com.apple.JavaScriptCore 	0x05ccca5c KJS::AddNode::evaluate(KJS::ExecState*) + 232 (nodes.cpp:
1040)
28  com.apple.JavaScriptCore 	0x05ccc9c8 KJS::AddNode::evaluate(KJS::ExecState*) + 84 (nodes.cpp:
1037)
29  com.apple.JavaScriptCore 	0x05ccc9c8 KJS::AddNode::evaluate(KJS::ExecState*) + 84 (nodes.cpp:
1037)
30  com.apple.JavaScriptCore 	0x05cd5638 KJS::AssignResolveNode::evaluate(KJS::ExecState*) + 636 
(nodes.cpp:1306)
31  com.apple.JavaScriptCore 	0x05ccf0e0 KJS::ExprStatementNode::execute(KJS::ExecState*) + 220 
(nodes.cpp:1594)
32  com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
33  com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
34  com.apple.JavaScriptCore 	0x05cd1900 KJS::ForInNode::execute(KJS::ExecState*) + 3028 
(nodes.cpp:1860)
35  com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
36  com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
37  com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
38  com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
39  com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
40  com.apple.JavaScriptCore 	0x05cca148 KJS::FunctionCallBracketNode::evaluate(KJS::ExecState*) + 
1232 (nodes.cpp:602)
41  com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
42  com.apple.JavaScriptCore 	0x05ccded4 KJS::StatListNode::execute(KJS::ExecState*) + 104 
(nodes.cpp:1423)
43  com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
44  com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
45  com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
46  com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
47  com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
48  com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
49  com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
50  com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
51  com.apple.JavaScriptCore 	0x05cca568 KJS::FunctionCallDotNode::evaluate(KJS::ExecState*) + 904 
(nodes.cpp:641)
52  com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
53  com.apple.JavaScriptCore 	0x05cce054 KJS::StatListNode::execute(KJS::ExecState*) + 488 
(nodes.cpp:1431)
54  com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
55  com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
56  com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
57  com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
58  com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
59  com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
60  com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
61  com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
62  com.apple.JavaScriptCore 	0x05cca148 KJS::FunctionCallBracketNode::evaluate(KJS::ExecState*) + 
1232 (nodes.cpp:602)
63  com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
64  com.apple.JavaScriptCore 	0x05ccded4 KJS::StatListNode::execute(KJS::ExecState*) + 104 
(nodes.cpp:1423)
65  com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
66  com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
67  com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
68  com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
69  com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
70  com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
71  com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
72  com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
73  com.apple.JavaScriptCore 	0x05cca568 KJS::FunctionCallDotNode::evaluate(KJS::ExecState*) + 904 
(nodes.cpp:641)
74  com.apple.JavaScriptCore 	0x05cce358 KJS::AssignExprNode::evaluate(KJS::ExecState*) + 84 
(nodes.cpp:1454)
75  com.apple.JavaScriptCore 	0x05cce544 KJS::VarDeclNode::evaluate(KJS::ExecState*) + 168 
(nodes.cpp:1472)
76  com.apple.JavaScriptCore 	0x05cce89c KJS::VarDeclListNode::evaluate(KJS::ExecState*) + 96 
(nodes.cpp:1520)
77  com.apple.JavaScriptCore 	0x05cceab0 KJS::VarStatementNode::execute(KJS::ExecState*) + 220 
(nodes.cpp:1539)
78  com.apple.JavaScriptCore 	0x05cd4f78 KJS::SourceElementsNode::execute(KJS::ExecState*) + 280 
(nodes.cpp:2316)
79  com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
80  com.apple.JavaScriptCore 	0x05cd1900 KJS::ForInNode::execute(KJS::ExecState*) + 3028 
(nodes.cpp:1860)
81  com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
82  com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
83  com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
84  com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
85  com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
86  com.apple.JavaScriptCore 	0x05cca148 KJS::FunctionCallBracketNode::evaluate(KJS::ExecState*) + 
1232 (nodes.cpp:602)
87  com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
88  com.apple.JavaScriptCore 	0x05ccded4 KJS::StatListNode::execute(KJS::ExecState*) + 104 
(nodes.cpp:1423)
89  com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
90  com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
91  com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
92  com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
93  com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
94  com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
95  com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
96  com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
97  com.apple.JavaScriptCore 	0x05cca568 KJS::FunctionCallDotNode::evaluate(KJS::ExecState*) + 904 
(nodes.cpp:641)
98  com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
99  com.apple.JavaScriptCore 	0x05cce054 KJS::StatListNode::execute(KJS::ExecState*) + 488 
(nodes.cpp:1431)
100 com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
101 com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
102 com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
103 com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
104 com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
105 com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
106 com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
107 com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
108 com.apple.JavaScriptCore 	0x05cca148 KJS::FunctionCallBracketNode::evaluate(KJS::ExecState*) + 
1232 (nodes.cpp:602)
109 com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
110 com.apple.JavaScriptCore 	0x05ccded4 KJS::StatListNode::execute(KJS::ExecState*) + 104 
(nodes.cpp:1423)
111 com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
112 com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
113 com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
114 com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
115 com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
116 com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
117 com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
118 com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
119 com.apple.JavaScriptCore 	0x05cca568 KJS::FunctionCallDotNode::evaluate(KJS::ExecState*) + 904 
(nodes.cpp:641)
120 com.apple.JavaScriptCore 	0x05cce358 KJS::AssignExprNode::evaluate(KJS::ExecState*) + 84 
(nodes.cpp:1454)
121 com.apple.JavaScriptCore 	0x05cce544 KJS::VarDeclNode::evaluate(KJS::ExecState*) + 168 
(nodes.cpp:1472)
122 com.apple.JavaScriptCore 	0x05cce89c KJS::VarDeclListNode::evaluate(KJS::ExecState*) + 96 
(nodes.cpp:1520)
123 com.apple.JavaScriptCore 	0x05cceab0 KJS::VarStatementNode::execute(KJS::ExecState*) + 220 
(nodes.cpp:1539)
124 com.apple.JavaScriptCore 	0x05cd4f78 KJS::SourceElementsNode::execute(KJS::ExecState*) + 280 
(nodes.cpp:2316)
125 com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
126 com.apple.JavaScriptCore 	0x05cd1900 KJS::ForInNode::execute(KJS::ExecState*) + 3028 
(nodes.cpp:1860)
127 com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
128 com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
129 com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
130 com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
131 com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
132 com.apple.JavaScriptCore 	0x05cca148 KJS::FunctionCallBracketNode::evaluate(KJS::ExecState*) + 
1232 (nodes.cpp:602)
133 com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
134 com.apple.JavaScriptCore 	0x05ccded4 KJS::StatListNode::execute(KJS::ExecState*) + 104 
(nodes.cpp:1423)
135 com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
136 com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
137 com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
138 com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
139 com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
140 com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
141 com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
142 com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
143 com.apple.JavaScriptCore 	0x05cca568 KJS::FunctionCallDotNode::evaluate(KJS::ExecState*) + 904 
(nodes.cpp:641)
144 com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
145 com.apple.JavaScriptCore 	0x05cce054 KJS::StatListNode::execute(KJS::ExecState*) + 488 
(nodes.cpp:1431)
146 com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
147 com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
148 com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
149 com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
150 com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
151 com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
152 com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
153 com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
154 com.apple.JavaScriptCore 	0x05cca148 KJS::FunctionCallBracketNode::evaluate(KJS::ExecState*) + 
1232 (nodes.cpp:602)
155 com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
156 com.apple.JavaScriptCore 	0x05ccded4 KJS::StatListNode::execute(KJS::ExecState*) + 104 
(nodes.cpp:1423)
157 com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
158 com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
159 com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
160 com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
161 com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
162 com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
163 com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
164 com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
165 com.apple.JavaScriptCore 	0x05cca568 KJS::FunctionCallDotNode::evaluate(KJS::ExecState*) + 904 
(nodes.cpp:641)
166 com.apple.JavaScriptCore 	0x05ccca5c KJS::AddNode::evaluate(KJS::ExecState*) + 232 (nodes.cpp:
1040)
167 com.apple.JavaScriptCore 	0x05ccc9c8 KJS::AddNode::evaluate(KJS::ExecState*) + 84 (nodes.cpp:
1037)
168 com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
169 com.apple.JavaScriptCore 	0x05cd4f78 KJS::SourceElementsNode::execute(KJS::ExecState*) + 280 
(nodes.cpp:2316)
170 com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
171 com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
172 com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
173 com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
174 com.apple.JavaScriptCore 	0x05cca148 KJS::FunctionCallBracketNode::evaluate(KJS::ExecState*) + 
1232 (nodes.cpp:602)
175 com.apple.JavaScriptCore 	0x05cd23c4 KJS::ReturnNode::execute(KJS::ExecState*) + 416 
(nodes.cpp:1933)
176 com.apple.JavaScriptCore 	0x05ccded4 KJS::StatListNode::execute(KJS::ExecState*) + 104 
(nodes.cpp:1423)
177 com.apple.JavaScriptCore 	0x05cd29a0 KJS::CaseClauseNode::evalStatements(KJS::ExecState*) + 
124 (nodes.cpp:1977)
178 com.apple.JavaScriptCore 	0x05cd2fec KJS::CaseBlockNode::evalBlock(KJS::ExecState*, 
KJS::ValueImp*) + 428 (nodes.cpp:2049)
179 com.apple.JavaScriptCore 	0x05cd3824 KJS::SwitchNode::execute(KJS::ExecState*) + 508 
(nodes.cpp:2119)
180 com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
181 com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
182 com.apple.JavaScriptCore 	0x05cb20b0 KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 
(function.cpp:337)
183 com.apple.JavaScriptCore 	0x05cb14c4 KJS::FunctionImp::callAsFunction(KJS::ExecState*, 
KJS::ObjectImp*, KJS::List const&) + 700 (function.cpp:109)
184 com.apple.JavaScriptCore 	0x05cdb7fc KJS::ObjectImp::call(KJS::ExecState*, KJS::ObjectImp*, 
KJS::List const&) + 288 (object.cpp:95)
185 com.apple.JavaScriptCore 	0x05cca568 KJS::FunctionCallDotNode::evaluate(KJS::ExecState*) + 904 
(nodes.cpp:641)
186 com.apple.JavaScriptCore 	0x05cc8600 KJS::GroupNode::evaluate(KJS::ExecState*) + 84 (nodes.cpp:
292)
187 com.apple.JavaScriptCore 	0x05cce358 KJS::AssignExprNode::evaluate(KJS::ExecState*) + 84 
(nodes.cpp:1454)
188 com.apple.JavaScriptCore 	0x05cce544 KJS::VarDeclNode::evaluate(KJS::ExecState*) + 168 
(nodes.cpp:1472)
189 com.apple.JavaScriptCore 	0x05cce89c KJS::VarDeclListNode::evaluate(KJS::ExecState*) + 96 
(nodes.cpp:1520)
190 com.apple.JavaScriptCore 	0x05cceab0 KJS::VarStatementNode::execute(KJS::ExecState*) + 220 
(nodes.cpp:1539)
191 com.apple.JavaScriptCore 	0x05cd50c8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 616 
(nodes.cpp:2322)
192 com.apple.JavaScriptCore 	0x05ccef10 KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:
1571)
193 com.apple.JavaScriptCore 	0x05cbf25c KJS::InterpreterImp::evaluate(KJS::UString const&, 
KJS::ValueImp*, KJS::UString const&, int) + 1036 (internal.cpp:727)
194 com.apple.JavaScriptCore 	0x05cc17b0 KJS::Interpreter::evaluate(KJS::UString const&, int, 
KJS::UString const&, KJS::ValueImp*) + 92 (interpreter.cpp:136)
195 com.apple.WebCore        	0x01111f80 KJSProxyImpl::evaluate(QString, int, QString const&, 
DOM::NodeImpl*) + 280 (kjs_proxy.cpp:118)
196 com.apple.WebCore        	0x0109a1f8 KHTMLPart::executeScript(QString, int, DOM::NodeImpl*, 
QString const&) + 240 (khtml_part.cpp:5346)
197 com.apple.WebCore        	0x011772cc khtml::HTMLTokenizer::scriptExecution(QString const&, 
QString, int) + 448 (htmltokenizer.cpp:506)
198 com.apple.WebCore        	0x01178364 khtml::HTMLTokenizer::scriptHandler() + 1396 
(htmltokenizer.cpp:447)
199 com.apple.WebCore        	0x0117892c khtml::HTMLTokenizer::parseSpecial
(khtml::TokenizerString&) + 1112 (htmltokenizer.cpp:336)
200 com.apple.WebCore        	0x0117ac9c khtml::HTMLTokenizer::parseTag(khtml::TokenizerString&) 
+ 7500 (htmltokenizer.cpp:1286)
201 com.apple.WebCore        	0x0117b4c4 khtml::HTMLTokenizer::write(khtml::TokenizerString 
const&, bool) + 1496 (htmltokenizer.cpp:1475)
202 com.apple.WebCore        	0x0117b9e4 khtml::HTMLTokenizer::notifyFinished
(khtml::CachedObject*) + 520 (htmltokenizer.cpp:1820)
203 com.apple.WebCore        	0x01183d58 khtml::CachedScript::checkNotify() + 140 (loader.cpp:323)
204 com.apple.WebCore        	0x01183edc khtml::CachedScript::data(QBuffer&, bool) + 276 
(loader.cpp:315)
205 com.apple.WebCore        	0x011887b0 khtml::Loader::slotFinished(KIO::Job*, NSData*) + 648 
(loader.cpp:1636)
206 com.apple.WebCore        	0x0122b438 KWQSlot::callWithData(KIO::Job*, NSData*) const + 108 
(KWQSlot.mm:320)
207 com.apple.WebCore        	0x01229f48 KWQSignal::callWithData(KIO::Job*, NSData*) const + 232 
(KWQSignal.mm:182)
208 com.apple.WebCore        	0x0103ad34 KIO::TransferJob::emitResult(NSData*) + 72 
(KWQKJobClasses.mm:242)
209 com.apple.WebCore        	0x01236a78 -[KWQResourceLoader finishJobAndHandle:] + 124 
(KWQResourceLoader.mm:94)
210 com.apple.WebCore        	0x01236d14 -[KWQResourceLoader finishWithData:] + 196 
(KWQResourceLoader.mm:125)
211 com.apple.WebKit         	0x00241ea0 -[WebSubresourceLoader didFinishLoading] + 132 
(WebSubresourceLoader.m:204)
212 com.apple.WebKit         	0x00252608 -[WebLoader connectionDidFinishLoading:] + 184 
(WebLoader.m:655)
213 com.apple.Foundation     	0x9290adbc -[NSURLConnection(NSURLConnectionInternal) 
_sendDidFinishLoadingCallback] + 188
214 com.apple.Foundation     	0x92909028 -[NSURLConnection(NSURLConnectionInternal) 
_sendCallbacks] + 556
215 com.apple.Foundation     	0x92908d80 _sendCallbacks + 156
216 com.apple.CoreFoundation 	0x9075da5c __CFRunLoopDoSources0 + 384
217 com.apple.CoreFoundation 	0x9075cf8c __CFRunLoopRun + 452
218 com.apple.CoreFoundation 	0x9075ca0c CFRunLoopRunSpecific + 268
219 com.apple.Foundation     	0x928e7744 -[NSRunLoop runMode:beforeDate:] + 172
220 DumpRenderTree           	0x00006414 dumpRenderTree + 740 (DumpRenderTree.m:561)
221 DumpRenderTree           	0x00003f50 main + 2244 (DumpRenderTree.m:169)
222 DumpRenderTree           	0x00002ee8 _start + 344 (crt.c:272)
223 DumpRenderTree           	0x00002d8c start + 60

Thread 1:
0   libSystem.B.dylib        	0x9000b208 mach_msg_trap + 8
1   libSystem.B.dylib        	0x9000b15c mach_msg + 60
2   com.apple.CoreFoundation 	0x9075d108 __CFRunLoopRun + 832
3   com.apple.CoreFoundation 	0x9075ca0c CFRunLoopRunSpecific + 268
4   com.apple.Foundation     	0x928ffc7c +[NSURLConnection(NSURLConnectionInternal) 
_resourceLoadLoop:] + 264
5   com.apple.Foundation     	0x928d87b4 forkThreadForFunction + 108
6   libSystem.B.dylib        	0x9002b200 _pthread_body + 96

Thread 2:
0   libSystem.B.dylib        	0x9000b208 mach_msg_trap + 8
1   libSystem.B.dylib        	0x9000b15c mach_msg + 60
2   com.apple.CoreFoundation 	0x9075d108 __CFRunLoopRun + 832
3   com.apple.CoreFoundation 	0x9075ca0c CFRunLoopRunSpecific + 268
4   com.apple.Foundation     	0x92900dbc +[NSURLCache _diskCacheSyncLoop:] + 152
5   com.apple.Foundation     	0x928d87b4 forkThreadForFunction + 108
6   libSystem.B.dylib        	0x9002b200 _pthread_body + 96

Thread 3:
0   libSystem.B.dylib        	0x9000b208 mach_msg_trap + 8
1   libSystem.B.dylib        	0x9000b15c mach_msg + 60
2   com.apple.CoreFoundation 	0x9075d108 __CFRunLoopRun + 832
3   com.apple.CoreFoundation 	0x9075ca0c CFRunLoopRunSpecific + 268
4   com.apple.Foundation     	0x928e7744 -[NSRunLoop runMode:beforeDate:] + 172
5   com.apple.Foundation     	0x928e767c -[NSRunLoop run] + 76
6   com.apple.WebKit         	0x002c4be0 +[WebFileDatabase _syncLoop:] + 420 
(WebFileDatabase.m:291)
7   com.apple.Foundation     	0x928d87b4 forkThreadForFunction + 108
8   libSystem.B.dylib        	0x9002b200 _pthread_body + 96

Thread 0 crashed with PPC Thread State 64:
  srr0: 0x0000000005d20f08 srr1: 0x000000000200d030                        vrsave: 
0x0000000000000000
    cr: 0x84000448          xer: 0x0000000000000004   lr: 0x0000000005d1d388  ctr: 
0x0000000005d20de8
    r0: 0x0000000000000001   r1: 0x00000000bfff7360   r2: 0x00000000e6209000   r3: 
0x00000000e6209000
    r4: 0x00000000e9a93ff7   r5: 0x0000000000000002   r6: 0x00000000bfff7978   r7: 
0x0000000000000000
    r8: 0x00000000bfff77f4   r9: 0x0000000000000027  r10: 0x0000000000000001  r11: 
0x00000000e9a93ff9
   r12: 0x000000009012c564  r13: 0x0000000000000000  r14: 0x0000000000000001  r15: 
0x0000000000000000
   r16: 0x0000000000000001  r17: 0x0000000000000000  r18: 0x0000000000000000  r19: 
0x0000000000000000
   r20: 0x0000000000000000  r21: 0x0000000000000000  r22: 0x0000000000000001  r23: 
0x00000000b202bfdc
   r24: 0x00000000a28d8dfc  r25: 0x0000000000000001  r26: 0x0000000000000003  r27: 
0x00000000a28d8dfc
   r28: 0x00000000e6208ff4  r29: 0x00000000e9a93fcc  r30: 0x00000000bfff7360  r31: 
0x0000000005d1d388

Binary Images Description:
    0x1000 -     0x7fff DumpRenderTree 	/Volumes/Stuff/Projects/build/Development/
DumpRenderTree
  0x205000 -   0x316fff com.apple.WebKit 420+	/Volumes/Stuff/Projects/build/Development/
WebKit.framework/Versions/A/WebKit
 0x1008000 -  0x13defff com.apple.WebCore 420+	/Volumes/Stuff/Projects/build/Development/
WebCore.framework/Versions/A/WebCore
 0x5ca1000 -  0x5d4efff com.apple.JavaScriptCore 420+	/Volumes/Stuff/Projects/build/Development/
JavaScriptCore.framework/Versions/A/JavaScriptCore
0x8fe00000 - 0x8fe54fff dyld 44.2	/usr/lib/dyld
0x90000000 - 0x901b3fff libSystem.B.dylib 	/usr/lib/libSystem.B.dylib
0x9020b000 - 0x9020ffff libmathCommon.A.dylib 	/usr/lib/system/libmathCommon.A.dylib
0x90211000 - 0x90264fff com.apple.CoreText 1.0.1 (???)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/CoreText.framework/Versions/A/CoreText
0x90291000 - 0x90342fff ATS 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ATS.framework/Versions/A/ATS
0x90371000 - 0x906aefff com.apple.CoreGraphics 1.256.22 (???)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
CoreGraphics.framework/Versions/A/CoreGraphics
0x9073a000 - 0x90813fff com.apple.CoreFoundation 6.4.4 (368.18)
	/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
0x9085c000 - 0x9085cfff com.apple.CoreServices 10.4 (???)	/System/Library/Frameworks/
CoreServices.framework/Versions/A/CoreServices
0x9085e000 - 0x90960fff libicucore.A.dylib 	/usr/lib/libicucore.A.dylib
0x909ba000 - 0x90a3efff libobjc.A.dylib 	/usr/lib/libobjc.A.dylib
0x90a68000 - 0x90ad6fff com.apple.framework.IOKit 1.4 (???)	/System/Library/Frameworks/
IOKit.framework/Versions/A/IOKit
0x90aed000 - 0x90afffff libauto.dylib 	/usr/lib/libauto.dylib
0x90b06000 - 0x90dddfff com.apple.CoreServices.CarbonCore 10.4.3 (659)
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
CarbonCore.framework/Versions/A/CarbonCore
0x90e43000 - 0x90ec3fff com.apple.CoreServices.OSServices 4.1
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
OSServices.framework/Versions/A/OSServices
0x90f0d000 - 0x90f4efff com.apple.CFNetwork 10.4.3 (129.2)
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
CFNetwork.framework/Versions/A/CFNetwork
0x90f63000 - 0x90f7bfff com.apple.WebServices 1.1.2 (1.1.0)	/System/Library/Frameworks/
CoreServices.framework/Versions/A/Frameworks/WebServicesCore.framework/Versions/A/
WebServicesCore
0x90f8b000 - 0x9100cfff com.apple.SearchKit 1.0.4	/System/Library/Frameworks/
CoreServices.framework/Versions/A/Frameworks/SearchKit.framework/Versions/A/SearchKit
0x91052000 - 0x9107bfff com.apple.Metadata 10.4.3 (121.20)
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
Metadata.framework/Versions/A/Metadata
0x9108c000 - 0x9109afff libz.1.dylib 	/usr/lib/libz.1.dylib
0x9109d000 - 0x9125ffff com.apple.security 4.2 (24844)	/System/Library/Frameworks/
Security.framework/Versions/A/Security
0x91362000 - 0x9136bfff com.apple.DiskArbitration 2.1	/System/Library/Frameworks/
DiskArbitration.framework/Versions/A/DiskArbitration
0x91372000 - 0x91399fff com.apple.SystemConfiguration 1.8.1
	/System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfiguration
0x913ac000 - 0x913b4fff libgcc_s.1.dylib 	/usr/lib/libgcc_s.1.dylib
0x913b9000 - 0x913d9fff libmx.A.dylib 	/usr/lib/libmx.A.dylib
0x913df000 - 0x913e7fff libbsm.dylib 	/usr/lib/libbsm.dylib
0x913eb000 - 0x91469fff com.apple.audio.CoreAudio 3.0.1	/System/Library/Frameworks/
CoreAudio.framework/Versions/A/CoreAudio
0x914a7000 - 0x914a7fff com.apple.ApplicationServices 10.4 (???)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/ApplicationServices
0x914a9000 - 0x914e1fff com.apple.AE 1.5 (297)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/AE.framework/Versions/A/AE
0x914fc000 - 0x915c9fff com.apple.ColorSync 4.4.3	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/ColorSync.framework/Versions/A/ColorSync
0x9161e000 - 0x916b1fff com.apple.print.framework.PrintCore 4.3 (172.3)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
PrintCore.framework/Versions/A/PrintCore
0x916f8000 - 0x917b5fff com.apple.QD 3.8.17 (???)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/QD.framework/Versions/A/QD
0x917f3000 - 0x91851fff com.apple.HIServices 1.5.1 (???)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/HIServices.framework/Versions/A/HIServices
0x9187f000 - 0x918a3fff com.apple.LangAnalysis 1.6.1	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/LangAnalysis.framework/Versions/A/
LangAnalysis
0x918b7000 - 0x918dcfff com.apple.FindByContent 1.5	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/FindByContent.framework/Versions/A/
FindByContent
0x918ef000 - 0x91931fff com.apple.LaunchServices 10.4.5 (166)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
LaunchServices.framework/Versions/A/LaunchServices
0x9194d000 - 0x91961fff com.apple.speech.synthesis.framework 3.3
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
SpeechSynthesis.framework/Versions/A/SpeechSynthesis
0x9196f000 - 0x919a6fff com.apple.ImageIO.framework 1.0.3
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
ImageIO.framework/Versions/A/ImageIO
0x919bb000 - 0x91a81fff libcrypto.0.9.7.dylib 	/usr/lib/libcrypto.0.9.7.dylib
0x91ace000 - 0x91ae3fff libcups.2.dylib 	/usr/lib/libcups.2.dylib
0x91ae8000 - 0x91b04fff libJPEG.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libJPEG.dylib
0x91b09000 - 0x91b78fff libJP2.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libJP2.dylib
0x91b8f000 - 0x91b93fff libGIF.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libGIF.dylib
0x91b95000 - 0x91bc5fff libRaw.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libRaw.dylib
0x91bc9000 - 0x91c0cfff libTIFF.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libTIFF.dylib
0x91c13000 - 0x91c2cfff libPng.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libPng.dylib
0x91c31000 - 0x91c34fff libRadiance.dylib 	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/
libRadiance.dylib
0x91c36000 - 0x91c36fff com.apple.Accelerate 1.1.1 (Accelerate 1.1.1)
	/System/Library/Frameworks/Accelerate.framework/Versions/A/Accelerate
0x91c38000 - 0x91d22fff com.apple.vImage 2.0	/System/Library/Frameworks/
Accelerate.framework/Versions/A/Frameworks/vImage.framework/Versions/A/vImage
0x91d2a000 - 0x91d49fff com.apple.Accelerate.vecLib 3.1.1 (vecLib 3.1.1)
	/System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/
Versions/A/vecLib
0x91db5000 - 0x91e1afff libvMisc.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libvMisc.dylib
0x91e24000 - 0x91eb6fff libvDSP.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libvDSP.dylib
0x91ed0000 - 0x92460fff libBLAS.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libBLAS.dylib
0x924a8000 - 0x927b8fff libLAPACK.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libLAPACK.dylib
0x927e5000 - 0x92871fff com.apple.DesktopServices 1.3.1	/System/Library/PrivateFrameworks/
DesktopServicesPriv.framework/Versions/A/DesktopServicesPriv
0x928b3000 - 0x92addfff com.apple.Foundation 6.4.2 (567.17)
	/System/Library/Frameworks/Foundation.framework/Versions/C/Foundation
0x92bfb000 - 0x92cd9fff libxml2.2.dylib 	/usr/lib/libxml2.2.dylib
0x92cf9000 - 0x92de7fff libiconv.2.dylib 	/usr/lib/libiconv.2.dylib
0x92df9000 - 0x92e17fff libGL.dylib 	/System/Library/Frameworks/OpenGL.framework/Versions/
A/Libraries/libGL.dylib
0x92e22000 - 0x92e7cfff libGLU.dylib 	/System/Library/Frameworks/OpenGL.framework/Versions/
A/Libraries/libGLU.dylib
0x92e9a000 - 0x92e9afff com.apple.Carbon 10.4 (???)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Carbon
0x92e9c000 - 0x92eb0fff com.apple.ImageCapture 3.0	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/ImageCapture.framework/Versions/A/ImageCapture
0x92ec8000 - 0x92ed8fff com.apple.speech.recognition.framework 3.4
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
SpeechRecognition.framework/Versions/A/SpeechRecognition
0x92ee4000 - 0x92ef9fff com.apple.securityhi 2.0 (203)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/SecurityHI.framework/Versions/A/SecurityHI
0x92f0b000 - 0x92f92fff com.apple.ink.framework 101.2 (69)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/Ink.framework/Versions/A/Ink
0x92fa6000 - 0x92fb1fff com.apple.help 1.0.3 (32)	/System/Library/Frameworks/Carbon.framework/
Versions/A/Frameworks/Help.framework/Versions/A/Help
0x92fbb000 - 0x92fe8fff com.apple.openscripting 1.2.2 (???)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/OpenScripting.framework/Versions/A/OpenScripting
0x93002000 - 0x93012fff com.apple.print.framework.Print 5.0 (190.1)
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Print.framework/
Versions/A/Print
0x9301e000 - 0x93084fff com.apple.htmlrendering 1.1.2	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/HTMLRendering.framework/Versions/A/HTMLRendering
0x930b5000 - 0x93107fff com.apple.NavigationServices 3.4.2
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
NavigationServices.framework/Versions/A/NavigationServices
0x93133000 - 0x93150fff com.apple.audio.SoundManager 3.9
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
CarbonSound.framework/Versions/A/CarbonSound
0x93162000 - 0x9316ffff com.apple.CommonPanels 1.2.2 (73)
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
CommonPanels.framework/Versions/A/CommonPanels
0x93178000 - 0x9348afff com.apple.HIToolbox 1.4.4 (???)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/HIToolbox.framework/Versions/A/HIToolbox
0x935d6000 - 0x935e2fff com.apple.opengl 1.4.5	/System/Library/Frameworks/OpenGL.framework/
Versions/A/OpenGL
0x93674000 - 0x93674fff com.apple.Cocoa 6.4 (???)	/System/Library/Frameworks/
Cocoa.framework/Versions/A/Cocoa
0x93676000 - 0x93ca9fff com.apple.AppKit 6.4.3 (824.17)	/System/Library/Frameworks/
AppKit.framework/Versions/C/AppKit
0x94035000 - 0x940a4fff com.apple.CoreData 50 (53)	/System/Library/Frameworks/
CoreData.framework/Versions/A/CoreData
0x940dd000 - 0x941a7fff com.apple.audio.toolbox.AudioToolbox 1.4.1
	/System/Library/Frameworks/AudioToolbox.framework/Versions/A/AudioToolbox
0x941fb000 - 0x941fbfff com.apple.audio.units.AudioUnit 1.4
	/System/Library/Frameworks/AudioUnit.framework/Versions/A/AudioUnit
0x941fd000 - 0x94371fff com.apple.QuartzCore 1.4.3	/System/Library/Frameworks/
QuartzCore.framework/Versions/A/QuartzCore
0x943ba000 - 0x943f7fff libsqlite3.0.dylib 	/usr/lib/libsqlite3.0.dylib
0x943ff000 - 0x9444ffff libGLImage.dylib 	/System/Library/Frameworks/OpenGL.framework/
Versions/A/Libraries/libGLImage.dylib
0x94608000 - 0x94614fff libCSync.A.dylib 	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/
Resources/libCSync.A.dylib
0x94659000 - 0x94671fff libRIP.A.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libRIP.A.dylib
0x9549e000 - 0x95521fff libstdc++.6.dylib 	/usr/lib/libstdc++.6.dylib
0x9604c000 - 0x96075fff libxslt.1.dylib 	/usr/lib/libxslt.1.dylib
0x9c300000 - 0x9c302fff libgmalloc.dylib 	/usr/lib/libgmalloc.dylib

Model: PowerBook6,4, BootROM 4.8.3f1, 1 processors, PowerPC G4  (1.1), 1.33 GHz, 1.25 GB
Graphics: GeForce FX Go5200, GeForce FX Go5200, AGP, 64 MB
Memory Module: DIMM0/BUILT-IN, 256 MB, built-in, built-in
Memory Module: DIMM1/J31, 1 GB, DDR SDRAM, PC2700U-25330
AirPort: AirPort Extreme, 402.6 (3.90.34.0.p13)
Bluetooth: Version 1.6.6f20, 2 service, 0 devices, 1 incoming serial ports
Network Service: VPN (L2TP), PPP (L2TP), ppp0
Network Service: AirPort, AirPort, en1
Parallel ATA Device: MATSHITADVD-R   UJ-825, 
Parallel ATA Device: TOSHIBA MK6025GAS, 55.89 GB
USB Device: Bluetooth HCI, , Up to 12 Mb/sec, 500 mA
Comment 3 Eric Seidel (no email) 2005-09-29 07:32:05 PDT
Reproducible crasher, bumping to P1.
Comment 4 Eric Seidel (no email) 2005-09-29 08:17:10 PDT
Actually fast/js/string_replace.html is an even simpler test which fails:
run-webkit-tests --guard -v fast/js/string_replace.html
Comment 5 mitz 2005-09-29 09:34:55 PDT
I /think/ it's a bug in the PCRE_UTF16 mods, in pcre_exec.c:1812. If (md->end_subject - eptr == 0) then 
it's not okay for the code to look at the character at eptr (which is what GETCHARINC does).
Comment 6 mitz 2005-09-29 11:22:56 PDT
Created attachment 4093 [details]
suggested patch
Comment 7 mitz 2005-09-29 11:32:44 PDT
Comment on attachment 4093 [details]
suggested patch

Dealing with the half-surrogate-pair case may be too paranoid here.
Comment 8 mitz 2005-09-29 14:14:20 PDT
Created attachment 4097 [details]
updated patch

Fixed the same thing also at another place
Comment 9 Darin Adler 2005-09-29 14:52:21 PDT
Comment on attachment 4093 [details]
suggested patch

The line:

	  if IS_LEADING_SURROGATE(dc)

should really be

	  if (IS_LEADING_SURROGATE(dc))

because it's a bit yucky to depend on the parentheses inside the macro.
Otherwise, this looks great. r=me
Comment 10 Darin Adler 2005-09-29 14:54:37 PDT
Comment on attachment 4097 [details]
updated patch

I think that it might be better to have a GETCHARINC macro that took an end
pointer and returned a special value rather than repeating this logic in
multiple places. That having been said, the patch looks fine except for the
parenthesis issue I mentioned in my earlier comment. r=me