<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>121648</bug_id>
          
          <creation_ts>2013-09-19 17:16:13 -0700</creation_ts>
          <short_desc>REGRESSION(r156047): WebCore hangs inside JSC::toInt32(double)</short_desc>
          <delta_ts>2013-09-20 17:06:28 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>JavaScriptCore</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar, Regression</keywords>
          <priority>P1</priority>
          <bug_severity>Critical</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>121064</dependson>
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ryosuke Niwa">rniwa</reporter>
          <assigned_to name="Filip Pizlo">fpizlo</assigned_to>
          <cc>barraclough</cc>
    
    <cc>fpizlo</cc>
    
    <cc>ggaren</cc>
    
    <cc>oliver</cc>
    
    <cc>slewis</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>931136</commentid>
    <comment_count>0</comment_count>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2013-09-19 17:16:13 -0700</bug_when>
    <thetext>e.g.

Running Time	Self		Symbol Name
15006.0ms   44.2%	15006.0	 	JSC::toInt32(double)
3067.0ms    9.0%	0.0	 	 &lt;Unknown Address&gt;
2214.0ms    6.5%	0.0	 	 0x3465719f9a52
2214.0ms    6.5%	0.0	 	  JSC::JITCode::execute(JSC::JSStack*, JSC::ExecState*, JSC::VM*)
2214.0ms    6.5%	0.0	 	   JSC::Interpreter::executeCall(JSC::ExecState*, JSC::JSObject*, JSC::CallType, JSC::CallData const&amp;, JSC::JSValue, JSC::ArgList const&amp;)
2214.0ms    6.5%	0.0	 	    JSC::call(JSC::ExecState*, JSC::JSValue, JSC::CallType, JSC::CallData const&amp;, JSC::JSValue, JSC::ArgList const&amp;)
2214.0ms    6.5%	0.0	 	     WebCore::JSEventListener::handleEvent(WebCore::ScriptExecutionContext*, WebCore::Event*)
2214.0ms    6.5%	0.0	 	      WebCore::EventTarget::fireEventListeners(WebCore::Event*, WebCore::EventTargetData*, WTF::Vector&lt;WebCore::RegisteredEventListener, 1ul, WTF::CrashOnOverflow&gt;&amp;)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>931138</commentid>
    <comment_count>1</comment_count>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2013-09-19 17:18:29 -0700</bug_when>
    <thetext>&lt;rdar://problem/15024481&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>931678</commentid>
    <comment_count>2</comment_count>
      <attachid>212246</attachid>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2013-09-20 17:00:45 -0700</bug_when>
    <thetext>Created attachment 212246
the patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>931680</commentid>
    <comment_count>3</comment_count>
      <attachid>212246</attachid>
    <who name="Mark Hahnenberg">mhahnenberg</who>
    <bug_when>2013-09-20 17:04:22 -0700</bug_when>
    <thetext>Comment on attachment 212246
the patch

r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>931681</commentid>
    <comment_count>4</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2013-09-20 17:06:28 -0700</bug_when>
    <thetext>Landed in http://trac.webkit.org/changeset/156212</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>212246</attachid>
            <date>2013-09-20 17:00:45 -0700</date>
            <delta_ts>2013-09-20 17:04:22 -0700</delta_ts>
            <desc>the patch</desc>
            <filename>blah.patch</filename>
            <type>text/plain</type>
            <size>4206</size>
            <attacher name="Filip Pizlo">fpizlo</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9DaGFuZ2VMb2cKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkocmV2aXNpb24gMTU2MjA5KQorKysgU291cmNl
L0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE3IEBA
CisyMDEzLTA5LTIwICBGaWxpcCBQaXpsbyAgPGZwaXpsb0BhcHBsZS5jb20+CisKKyAgICAgICAg
UkVHUkVTU0lPTihyMTU2MDQ3KTogV2ViQ29yZSBoYW5ncyBpbnNpZGUgSlNDOjp0b0ludDMyKGRv
dWJsZSkKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTEy
MTY0OAorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorICAgICAgICAKKyAg
ICAgICAgVGhlIEludDUyPC0+U3RyaWN0SW50NTIgY29udmVyc2lvbiBkaWQgdGhlIG9wcG9zaXRl
IGZpbGwoKSB0aGFuIHdoYXQgaXQgd2FzCisgICAgICAgIHN1cHBvc2VkIHRvLiBGb3IgZXhhbXBs
ZSB3aGVuIGNvbnZlcnRpbmcgYSBJbnQ1MiB0byBhIFN0cmljdEludDUyIGl0IHdvdWxkIGZpbGwK
KyAgICAgICAgYXMgSW50NTIsIGFuZCB2aWNlLXZlcnNhLgorCisgICAgICAgICogZGZnL0RGR1Nw
ZWN1bGF0aXZlSklUNjQuY3BwOgorICAgICAgICAoSlNDOjpERkc6OlNwZWN1bGF0aXZlSklUOjpm
aWxsU3BlY3VsYXRlSW50NTIpOgorCiAyMDEzLTA5LTIwICBNYXJrIEhhaG5lbmJlcmcgIDxtaGFo
bmVuYmVyZ0BhcHBsZS5jb20+CiAKICAgICAgICAgQ2xvYmJlcml6ZSBwaGFzZSBmb3JnZXRzIHRv
IGluZGljYXRlIHRoYXQgaXQgd3JpdGVzIEdDU3RhdGUgZm9yIHNldmVyYWwgbm9kZSB0eXBlcwpJ
bmRleDogU291cmNlL0phdmFTY3JpcHRDb3JlL2RmZy9ERkdTcGVjdWxhdGl2ZUpJVDY0LmNwcAo9
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09Ci0tLSBTb3VyY2UvSmF2YVNjcmlwdENvcmUvZGZnL0RGR1NwZWN1bGF0aXZlSklU
NjQuY3BwCShyZXZpc2lvbiAxNTYxMjEpCisrKyBTb3VyY2UvSmF2YVNjcmlwdENvcmUvZGZnL0RG
R1NwZWN1bGF0aXZlSklUNjQuY3BwCSh3b3JraW5nIGNvcHkpCkBAIC0xMTExLDcgKzExMTEsNyBA
QCBHUFJSZWcgU3BlY3VsYXRpdmVKSVQ6OmZpbGxTcGVjdWxhdGVJbnQ1CiAgICAgICAgICAgICB1
bmxvY2soZ3ByKTsKICAgICAgICAgICAgIGdwciA9IHJlc3VsdDsKICAgICAgICAgfSBlbHNlCi0g
ICAgICAgICAgICBpbmZvLmZpbGxTdHJpY3RJbnQ1MigqbV9zdHJlYW0sIGdwcik7CisgICAgICAg
ICAgICBpbmZvLmZpbGxJbnQ1MigqbV9zdHJlYW0sIGdwcik7CiAgICAgICAgIG1faml0LmxzaGlm
dDY0KFRydXN0ZWRJbW0zMihKU1ZhbHVlOjppbnQ1MlNoaWZ0QW1vdW50KSwgZ3ByKTsKICAgICAg
ICAgcmV0dXJuIGdwcjsKICAgICB9CkBAIC0xMTI4LDcgKzExMjgsNyBAQCBHUFJSZWcgU3BlY3Vs
YXRpdmVKSVQ6OmZpbGxTcGVjdWxhdGVJbnQ1CiAgICAgICAgICAgICB1bmxvY2soZ3ByKTsKICAg
ICAgICAgICAgIGdwciA9IHJlc3VsdDsKICAgICAgICAgfSBlbHNlCi0gICAgICAgICAgICBpbmZv
LmZpbGxJbnQ1MigqbV9zdHJlYW0sIGdwcik7CisgICAgICAgICAgICBpbmZvLmZpbGxTdHJpY3RJ
bnQ1MigqbV9zdHJlYW0sIGdwcik7CiAgICAgICAgIG1faml0LnJzaGlmdDY0KFRydXN0ZWRJbW0z
MihKU1ZhbHVlOjppbnQ1MlNoaWZ0QW1vdW50KSwgZ3ByKTsKICAgICAgICAgcmV0dXJuIGdwcjsK
ICAgICB9CkluZGV4OiBMYXlvdXRUZXN0cy9DaGFuZ2VMb2cKPT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gTGF5b3V0
VGVzdHMvQ2hhbmdlTG9nCShyZXZpc2lvbiAxNTYyMTEpCisrKyBMYXlvdXRUZXN0cy9DaGFuZ2VM
b2cJKHdvcmtpbmcgY29weSkKQEAgLTEsMyArMSwxNSBAQAorMjAxMy0wOS0yMCAgRmlsaXAgUGl6
bG8gIDxmcGl6bG9AYXBwbGUuY29tPgorCisgICAgICAgIFJFR1JFU1NJT04ocjE1NjA0Nyk6IFdl
YkNvcmUgaGFuZ3MgaW5zaWRlIEpTQzo6dG9JbnQzMihkb3VibGUpCisgICAgICAgIGh0dHBzOi8v
YnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0xMjE2NDgKKworICAgICAgICBSZXZpZXdl
ZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICAqIGpzL2RmZy1pbnQ1Mi1jaGFuZ2UtZm9y
bWF0LWV4cGVjdGVkLnR4dDogQWRkZWQuCisgICAgICAgICoganMvZGZnLWludDUyLWNoYW5nZS1m
b3JtYXQuaHRtbDogQWRkZWQuCisgICAgICAgICoganMvc2NyaXB0LXRlc3RzL2RmZy1pbnQ1Mi1j
aGFuZ2UtZm9ybWF0LmpzOiBBZGRlZC4KKyAgICAgICAgKGZvbyk6CisKIDIwMTMtMDktMjAgIE9s
aXZlciBIdW50ICA8b2xpdmVyQGFwcGxlLmNvbT4KIAogICAgICAgICBSRUdSRVNTSU9OKHIxNTMy
MTUpOiBOZXcgaUNsb3VkIHNpdGUgY3Jhc2hlcwpJbmRleDogTGF5b3V0VGVzdHMvanMvZGZnLWlu
dDUyLWNoYW5nZS1mb3JtYXQtZXhwZWN0ZWQudHh0Cj09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIExheW91dFRlc3Rz
L2pzL2RmZy1pbnQ1Mi1jaGFuZ2UtZm9ybWF0LWV4cGVjdGVkLnR4dAkocmV2aXNpb24gMCkKKysr
IExheW91dFRlc3RzL2pzL2RmZy1pbnQ1Mi1jaGFuZ2UtZm9ybWF0LWV4cGVjdGVkLnR4dAkod29y
a2luZyBjb3B5KQpAQCAtMCwwICsxLDUgQEAKK1BBU1MgZm9vKDEwMDAwMDAwMDApIGlzIFs0MDAw
MDAwMDAwLDgwMDAwMDAwMDAsLTE0NzQ4MzY0OCwxMjAwMDAwMDAwMF0gb24gYWxsIGl0ZXJhdGlv
bnMgaW5jbHVkaW5nIGFmdGVyIERGRyB0aWVyLXVwLgorUEFTUyBzdWNjZXNzZnVsbHlQYXJzZWQg
aXMgdHJ1ZQorCitURVNUIENPTVBMRVRFCisKSW5kZXg6IExheW91dFRlc3RzL2pzL2RmZy1pbnQ1
Mi1jaGFuZ2UtZm9ybWF0Lmh0bWwKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gTGF5b3V0VGVzdHMvanMvZGZnLWlu
dDUyLWNoYW5nZS1mb3JtYXQuaHRtbAkocmV2aXNpb24gMCkKKysrIExheW91dFRlc3RzL2pzL2Rm
Zy1pbnQ1Mi1jaGFuZ2UtZm9ybWF0Lmh0bWwJKHdvcmtpbmcgY29weSkKQEAgLTAsMCArMSwxMCBA
QAorPCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTC8vRU4iPgorPGh0bWw+
Cis8aGVhZD4KKzxzY3JpcHQgc3JjPSIuLi9yZXNvdXJjZXMvanMtdGVzdC1wcmUuanMiPjwvc2Ny
aXB0PgorPC9oZWFkPgorPGJvZHk+Cis8c2NyaXB0IHNyYz0ic2NyaXB0LXRlc3RzL2RmZy1pbnQ1
Mi1jaGFuZ2UtZm9ybWF0LmpzIj48L3NjcmlwdD4KKzxzY3JpcHQgc3JjPSIuLi9yZXNvdXJjZXMv
anMtdGVzdC1wb3N0LmpzIj48L3NjcmlwdD4KKzwvYm9keT4KKzwvaHRtbD4KSW5kZXg6IExheW91
dFRlc3RzL2pzL3NjcmlwdC10ZXN0cy9kZmctaW50NTItY2hhbmdlLWZvcm1hdC5qcwo9PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09Ci0tLSBMYXlvdXRUZXN0cy9qcy9zY3JpcHQtdGVzdHMvZGZnLWludDUyLWNoYW5nZS1mb3Jt
YXQuanMJKHJldmlzaW9uIDApCisrKyBMYXlvdXRUZXN0cy9qcy9zY3JpcHQtdGVzdHMvZGZnLWlu
dDUyLWNoYW5nZS1mb3JtYXQuanMJKHdvcmtpbmcgY29weSkKQEAgLTAsMCArMSwxNCBAQAorZnVu
Y3Rpb24gZm9vKGEpIHsKKyAgICAvLyBDcmVhdGUgYW4gaW50NTIuCisgICAgdmFyIHggPSBhICsg
MzAwMDAwMDAwMDsKKyAgICAvLyBNYWtlIHN1cmUgaXQncyBsZWZ0LXNoaWZ0ZWQuCisgICAgdmFy
IHkgPSB4ICsgeDsKKyAgICAvLyBOb3cgZ2V0IGl0IHRvIGJlIHJpZ2h0LXNoaWZ0ZWQuCisgICAg
dmFyIHogPSB4ID4+IDE7CisgICAgLy8gQW5kIGZpbmFsbHksIGRvIHNvbWV0aGluZyB0aGF0IHBy
ZWZlcnMgbGVmdC1zaGlmdC4KKyAgICB2YXIgdyA9IHkgKyB4OworICAgIHJldHVybiBbeCwgeSwg
eiwgd107Cit9CisKK2RmZ1Nob3VsZEJlKGZvbywgImZvbygxMDAwMDAwMDAwKSIsICJbNDAwMDAw
MDAwMCw4MDAwMDAwMDAwLC0xNDc0ODM2NDgsMTIwMDAwMDAwMDBdIik7CisK
</data>
<flag name="review"
          id="234425"
          type_id="1"
          status="+"
          setter="mhahnenberg"
    />
          </attachment>
      

    </bug>

</bugzilla>