<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>111059</bug_id>
          
          <creation_ts>2013-02-28 02:18:57 -0800</creation_ts>
          <short_desc>Crash in JSC::MarkedBlock::FreeList JSC::MarkedBlock::sweepHelper</short_desc>
          <delta_ts>2019-05-02 16:18:09 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>JavaScriptCore</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ryosuke Niwa">rniwa</reporter>
          <assigned_to name="Oliver Hunt">oliver</assigned_to>
          <cc>arkr17997</cc>
    
    <cc>benjamin</cc>
    
    <cc>cmarcelo</cc>
    
    <cc>fpizlo</cc>
    
    <cc>ggaren</cc>
    
    <cc>msaboff</cc>
    
    <cc>ojan.autocc</cc>
    
    <cc>oliver</cc>
    
    <cc>webkit.review.bot</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>843909</commentid>
    <comment_count>0</comment_count>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2013-02-28 02:18:57 -0800</bug_when>
    <thetext>CRASHING TEST: fast/js/regress/int-or-other-add-then-get-by-val.html

Thread 0 Crashed:: Dispatch queue: com.apple.main-thread
0   com.apple.JavaScriptCore      	0x000000010422be86 WTF::TCMalloc_ThreadCache_FreeList::Validate(WTF::HardenedSLL, unsigned long) + 70 (FastMalloc.cpp:2626)
1   com.apple.JavaScriptCore      	0x000000010422bd11 WTF::TCMalloc_ThreadCache::Deallocate(WTF::HardenedSLL, unsigned long) + 209 (FastMalloc.cpp:3247)
2   com.apple.JavaScriptCore      	0x0000000104147345 JSC::MarkedBlock::FreeList JSC::MarkedBlock::sweepHelper&lt;(JSC::MarkedBlock::DestructorType)2&gt;(JSC::MarkedBlock::SweepMode) + 309 (JSCell.h:117)
3   com.apple.JavaScriptCore      	0x0000000104146f57 JSC::MarkedBlock::sweep(JSC::MarkedBlock::SweepMode) + 71 (MarkedBlock.cpp:118)
4   com.apple.JavaScriptCore      	0x000000010406864c JSC::IncrementalSweeper::doSweep(double) + 108 (IncrementalSweeper.cpp:130)
5   com.apple.JavaScriptCore      	0x0000000104066c03 JSC::HeapTimer::timerDidFire(__CFRunLoopTimer*, void*) + 179 (TimeoutChecker.h:57)
6   com.apple.CoreFoundation      	0x00007fff92ac7da4 __CFRUNLOOP_IS_CALLING_OUT_TO_A_TIMER_CALLBACK_FUNCTION__ + 20
7   com.apple.CoreFoundation      	0x00007fff92ac78bd __CFRunLoopDoTimer + 557
8   com.apple.CoreFoundation      	0x00007fff92aad099 __CFRunLoopRun + 1513
9   com.apple.CoreFoundation      	0x00007fff92aac6b2 CFRunLoopRunSpecific + 290
10  com.apple.Foundation          	0x00007fff87a8089e -[NSRunLoop(NSRunLoop) runMode:beforeDate:] + 268
11  DumpRenderTree                	0x0000000103e33e12 runTest(std::__1::basic_string&lt;char, std::__1::char_traits&lt;char&gt;, std::__1::allocator&lt;char&gt; &gt; const&amp;) + 1639 (DumpRenderTree.mm:1375)
12  DumpRenderTree                	0x0000000103e335a6 dumpRenderTree(int, char const**) + 1727 (DumpRenderTree.mm:832)
13  DumpRenderTree                	0x0000000103e3417b main + 86 (DumpRenderTree.mm:925)
14  libdyld.dylib                 	0x00007fff895837e1 start + 1

e.g.
http://build.webkit.org/results/Apple%20MountainLion%20Release%20WK1%20(Tests)/r144275%20(7359)/results.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>844315</commentid>
    <comment_count>1</comment_count>
    <who name="Oliver Hunt">oliver</who>
    <bug_when>2013-02-28 11:54:36 -0800</bug_when>
    <thetext>So with some fiddling i can make this die fairly easily, implying a validation logic bug.  Can&apos;t work out of course, and lldb is trying hard to beat gdb for the prize of &quot;least good at debugging optimized code&quot; so seeing if i can make it repro in a debug build</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>844334</commentid>
    <comment_count>2</comment_count>
      <attachid>190776</attachid>
    <who name="Oliver Hunt">oliver</who>
    <bug_when>2013-02-28 12:10:31 -0800</bug_when>
    <thetext>Created attachment 190776
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>844337</commentid>
    <comment_count>3</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2013-02-28 12:13:22 -0800</bug_when>
    <thetext>r=me too</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>844339</commentid>
    <comment_count>4</comment_count>
    <who name="Oliver Hunt">oliver</who>
    <bug_when>2013-02-28 12:15:06 -0800</bug_when>
    <thetext>Committed r144346: &lt;http://trac.webkit.org/changeset/144346&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>844346</commentid>
    <comment_count>5</comment_count>
    <who name="Benjamin Poulain">benjamin</who>
    <bug_when>2013-02-28 12:20:27 -0800</bug_when>
    <thetext>Was it doing implicit conversion to bool prior to the operator?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>844349</commentid>
    <comment_count>6</comment_count>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2013-02-28 12:21:24 -0800</bug_when>
    <thetext>(In reply to comment #5)
&gt; Was it doing implicit conversion to bool prior to the operator?

Yup :(</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>190776</attachid>
            <date>2013-02-28 12:10:31 -0800</date>
            <delta_ts>2013-02-28 12:12:37 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-111059-20130228120644.patch</filename>
            <type>text/plain</type>
            <size>1484</size>
            <attacher name="Oliver Hunt">oliver</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTQ0MzMzCmRpZmYgLS1naXQgYS9Tb3VyY2UvV1RGL0NoYW5n
ZUxvZyBiL1NvdXJjZS9XVEYvQ2hhbmdlTG9nCmluZGV4IGViM2RjNjc0ZjAxYzFlZjFiNDdiMGY4
MzFjNTEzZjhkMDFjOWQ5NWQuLjJhY2RhNjhlNmNlMzI3N2IxYjUyNzI2MjkwZTUzYWFhYzBmNzU3
MGQgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XVEYvQ2hhbmdlTG9nCisrKyBiL1NvdXJjZS9XVEYvQ2hh
bmdlTG9nCkBAIC0xLDMgKzEsMTggQEAKKzIwMTMtMDItMjggIE9saXZlciBIdW50ICA8b2xpdmVy
QGFwcGxlLmNvbT4KKworICAgICAgICBDcmFzaCBpbiBKU0M6Ok1hcmtlZEJsb2NrOjpGcmVlTGlz
dCBKU0M6Ok1hcmtlZEJsb2NrOjpzd2VlcEhlbHBlcgorICAgICAgICBodHRwczovL2J1Z3Mud2Vi
a2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9MTExMDU5CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9C
T0RZIChPT1BTISkuCisKKyAgICAgICAgU29tZXRpbWVzIEMrKydzIGltcGxpY2l0IG9wZXJhdG9y
IGNvbnZlcnNpb24gcnVsZXMgc3Vjay4KKyAgICAgICAgQWRkIGV4cGxpY2l0IG9wZXJhdG9yPT0g
YW5kICE9LgorCisgICAgICAgICogd3RmL0Zhc3RNYWxsb2MuY3BwOgorICAgICAgICAoV1RGOjpI
YXJkZW5lZFNMTDo6b3BlcmF0b3IhPSk6CisgICAgICAgIChXVEY6OkhhcmRlbmVkU0xMOjpvcGVy
YXRvcj09KToKKyAgICAgICAgKEhhcmRlbmVkU0xMKToKKwogMjAxMy0wMi0yNyAgQmFsYXpzIEtp
bHZhZHkgIDxraWx2YWR5YkBob21lamlubmkuY29tPgogCiAgICAgICAgIEJ1ZyBpbiBhdG9taWNJ
bmNyZW1lbnQgaW1wbGVtZW50YXRpb24gZm9yIE1JUFMgR0NDCmRpZmYgLS1naXQgYS9Tb3VyY2Uv
V1RGL3d0Zi9GYXN0TWFsbG9jLmNwcCBiL1NvdXJjZS9XVEYvd3RmL0Zhc3RNYWxsb2MuY3BwCmlu
ZGV4IGRjOTI0NGZiYmJjZjU4NjFhODFlMzdlZGM1MmEyOWM5MmY0MGM1ZWEuLjJhMTE1ZjM0YzVj
MmIxNDFmYTYyZTA0MzY4ODhmZmFhYmEzMmU2MzYgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XVEYvd3Rm
L0Zhc3RNYWxsb2MuY3BwCisrKyBiL1NvdXJjZS9XVEYvd3RmL0Zhc3RNYWxsb2MuY3BwCkBAIC03
NzQsNiArNzc0LDkgQEAgcHVibGljOgogICAgIHR5cGVkZWYgdm9pZCogKEhhcmRlbmVkU0xMOjoq
VW5zcGVjaWZpZWRCb29sVHlwZSk7CiAgICAgQUxXQVlTX0lOTElORSBvcGVyYXRvciBVbnNwZWNp
ZmllZEJvb2xUeXBlKCkgY29uc3QgeyByZXR1cm4gbV92YWx1ZSA/ICZIYXJkZW5lZFNMTDo6bV92
YWx1ZSA6IDA7IH0KIAorICAgIGJvb2wgb3BlcmF0b3IhPShjb25zdCBIYXJkZW5lZFNMTCYgb3Ro
ZXIpIGNvbnN0IHsgcmV0dXJuIG1fdmFsdWUgIT0gb3RoZXIubV92YWx1ZTsgfQorICAgIGJvb2wg
b3BlcmF0b3I9PShjb25zdCBIYXJkZW5lZFNMTCYgb3RoZXIpIGNvbnN0IHsgcmV0dXJuIG1fdmFs
dWUgPT0gb3RoZXIubV92YWx1ZTsgfQorCiBwcml2YXRlOgogICAgIHZvaWQqIG1fdmFsdWU7CiB9
Owo=
</data>
<flag name="review"
          id="211550"
          type_id="1"
          status="+"
          setter="rniwa"
    />
          </attachment>
      

    </bug>

</bugzilla>