<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>124817</bug_id>
          
          <creation_ts>2013-11-24 11:12:59 -0800</creation_ts>
          <short_desc>[GTK] [Stable] WebProcess crashes in www.pressure.co.uk</short_desc>
          <delta_ts>2013-12-02 07:29:31 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKitGTK</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Alberto Garcia">berto</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>agomez</cc>
    
    <cc>cgarcia</cc>
    
    <cc>tesoro302</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>953851</commentid>
    <comment_count>0</comment_count>
    <who name="Alberto Garcia">berto</who>
    <bug_when>2013-11-24 11:12:59 -0800</bug_when>
    <thetext>WebKitGTK 2.2.2 is crashing while browsing http://www.pressure.co.uk/store/PS82/lee-perry-the-upsetters-roaring-lion/

I can reproduce this in epiphany and it&apos;s also reported to crash in Midori.

I haven&apos;t had the time to look into it yes, but it looks related to this:

** (WebKitWebProcess:29957): WARNING **: uri_tester_compile_regexp: Error while compiling regular expression /cdn-cgi/pe/bag\?r[]=.*cpalead.com at char 34: missing terminating ] for character class

(WebKitWebProcess:29957): GLib-CRITICAL **: g_regex_unref: assertion `regex != NULL&apos; failed</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>954233</commentid>
    <comment_count>1</comment_count>
    <who name="Andres Gomez Garcia">agomez</who>
    <bug_when>2013-11-26 00:35:45 -0800</bug_when>
    <thetext>Taking a look...</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>954474</commentid>
    <comment_count>2</comment_count>
    <who name="Andres Gomez Garcia">agomez</who>
    <bug_when>2013-11-27 00:29:46 -0800</bug_when>
    <thetext>(In reply to comment #0)
&gt; WebKitGTK 2.2.2 is crashing while browsing http://www.pressure.co.uk/store/PS82/lee-perry-the-upsetters-roaring-lion/
&gt; 
&gt; I can reproduce this in epiphany and it&apos;s also reported to crash in Midori.
...

I can reproduce this with ephy from Debian testing and webkitgtk:

$ dpkg -l | grep webkit
ii  libwebkit2gtk-3.0-25                 2.2.1-2                       amd64        Web content engine library for GTK+
ii  libwebkit2gtk-3.0-25-dbg             2.2.1-2                       amd64        Web content engine library for GTK+ - Debugging symbols
ii  libwebkitgtk-3.0-0                   2.2.1-2                       amd64        Web content engine library for GTK+
ii  libwebkitgtk-3.0-0-dbg               2.2.1-2                       amd64        Web content engine library for GTK+ - Debugging symbols
ii  libwebkitgtk-3.0-common              2.2.1-2                       all          Web content engine library for GTK+ - data files

$ dpkg -l | grep javascriptcore
ii  libjavascriptcoregtk-3.0-0           2.2.1-2                       amd64        Javascript engine library for GTK+
ii  libjavascriptcoregtk-3.0-0-dbg       2.2.1-2                       amd64        Javascript engine library for GTK+

&gt; I haven&apos;t had the time to look into it yes, but it looks related to this:
&gt; 
&gt; ** (WebKitWebProcess:29957): WARNING **: uri_tester_compile_regexp: Error while compiling regular expression /cdn-cgi/pe/bag\?r[]=.*cpalead.com at char 34: missing terminating ] for character class
&gt; 
&gt; (WebKitWebProcess:29957): GLib-CRITICAL **: g_regex_unref: assertion `regex != NULL&apos; failed

It doesn&apos;t look like.

This WARNING and CRITICAL are happening all the time and are coming from the adblock, which downloads the strings from:
https://easylist-downloads.adblockplus.org/easylist.txt

You can see that uri there.

Also, uri_tester_compile_regexp is epiphany&apos;s API. I will issue a bug there if there is none yet.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>954476</commentid>
    <comment_count>3</comment_count>
    <who name="Andres Gomez Garcia">agomez</who>
    <bug_when>2013-11-27 01:25:42 -0800</bug_when>
    <thetext>(In reply to comment #2)
&gt; Also, uri_tester_compile_regexp is epiphany&apos;s API. I will issue a bug there if there is none yet.

Reported at https://bugzilla.gnome.org/show_bug.cgi?id=719399</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>954527</commentid>
    <comment_count>4</comment_count>
    <who name="">tesoro302</who>
    <bug_when>2013-11-27 06:22:13 -0800</bug_when>
    <thetext>I&apos;m probably misunderstanding, but http://www.pressure.co.uk/store/PS82/lee-perry-the-upsetters-roaring-lion/ crashes for me with the &quot;Advertisement blocker&quot; extension disabled in midori.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>954718</commentid>
    <comment_count>5</comment_count>
    <who name="Andres Gomez Garcia">agomez</who>
    <bug_when>2013-11-28 06:37:47 -0800</bug_when>
    <thetext>(In reply to comment #4)
&gt; I&apos;m probably misunderstanding, but http://www.pressure.co.uk/store/PS82/lee-perry-the-upsetters-roaring-lion/ crashes for me with the &quot;Advertisement blocker&quot; extension disabled in midori.

As explained in comment #2 and comment #3, the WARNING and CRITICAL have been moved and solved in Epiphany at https://bugzilla.gnome.org/show_bug.cgi?id=719399

The SIGSEV is coming from WebKitGTK WebProcess, though.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>954719</commentid>
    <comment_count>6</comment_count>
    <who name="Andres Gomez Garcia">agomez</who>
    <bug_when>2013-11-28 06:40:38 -0800</bug_when>
    <thetext>SIGSEV confirmed in stable branch http://svn.webkit.org/repository/webkit/releases/WebKitGTK/webkit-2.2

Using MiniBrowser and a &quot;release&quot; build.

GDB&apos;s backtrace is not really informative:

&lt;pre&gt;
$ (gdb) bt
#0  0x00007fdd3a05bf33 in ?? ()
#1  0x00007fdd10495d40 in ?? ()
#2  0x000000000000000a in ?? ()
#3  0x00007fdd101b6920 in ?? ()
#4  0x00007fdd1031a010 in ?? ()
#5  0x00007fdd3a030e48 in ?? ()
#6  0x00007fdd10055090 in ?? ()
#7  0x00007fdd8c11b018 in ?? ()
#8  0x00007fdd8c11b018 in ?? ()
#9  0x00007fdd8c11b018 in ?? ()
#10 0x00007fdd3a00b8e0 in ?? ()
#11 0x00007fdd8c0f5e28 in ?? ()
#12 0x00007fdd297ea368 in ?? ()
#13 0x0000000000000000 in ?? ()
&lt;/pre&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>954733</commentid>
    <comment_count>7</comment_count>
    <who name="Andres Gomez Garcia">agomez</who>
    <bug_when>2013-11-28 07:35:16 -0800</bug_when>
    <thetext>Now, with a &quot;debug&quot; build and MiniBrowser, we have a SIGTRAP:

Program received signal SIGTRAP, Trace/breakpoint trap.
0x00007f114f94e5fc in ?? ()
(gdb) bt
#0  0x00007f114f94e5fc in ?? ()
#1  0x00007f114c1d0058 in ?? ()
#2  0x000000000000000a in ?? ()
#3  0x00000000020b3680 in ?? ()
#4  0x00007f113410a2b0 in ?? ()
#5  0x00007f118f8feda8 in ?? ()
#6  0x00007f1136e95d40 in ?? ()
#7  0x00007fffcae33f70 in ?? ()
#8  0x00007f11a3bc3f4a in JSC::MacroAssemblerCodeRef::operator! (this=0x7f119ed97f2a &lt;WebCore::JSDOMWindowBase::supportsRichSourceInfo(JSC::JSGlobalObject const*)&gt;) at ../../Source/JavaScriptCore/assembler/MacroAssemblerCodeRef.h:409
#9  0x00007f11a3bc38a8 in JSC::JITCode::execute (this=0x2084760, stack=0x1acb2d8, callFrame=0x7f114c1d0058, vm=0x1b21180) at ../../Source/JavaScriptCore/jit/JITCode.cpp:46
#10 0x00007f11a3baec75 in JSC::Interpreter::execute (this=0x1acb2c0, program=0x7f113433bff0, callFrame=0x7f114c06f9e0, thisObj=0x7f11a45bffd8) at ../../Source/JavaScriptCore/interpreter/Interpreter.cpp:766
#11 0x00007f11a3c93116 in JSC::evaluate (exec=0x7f114c06f9e0, source=..., thisValue=..., returnedException=0x7fffcae34c90) at ../../Source/JavaScriptCore/runtime/Completion.cpp:83
#12 0x00007f119edc3d79 in WebCore::JSMainThreadExecState::evaluate (exec=0x7f114c06f9e0, source=..., thisValue=..., exception=0x7fffcae34c90) at ../../Source/WebCore/bindings/js/JSMainThreadExecState.h:74
#13 0x00007f119edf1253 in WebCore::ScriptController::evaluateInWorld (this=0x1a02e50, sourceCode=..., world=0x1b1d230) at ../../Source/WebCore/bindings/js/ScriptController.cpp:142
#14 0x00007f119edf135c in WebCore::ScriptController::evaluate (this=0x1a02e50, sourceCode=...) at ../../Source/WebCore/bindings/js/ScriptController.cpp:158
#15 0x00007f119f0d0c4e in WebCore::ScriptElement::executeScript (this=0x20843b8, sourceCode=...) at ../../Source/WebCore/dom/ScriptElement.cpp:317
#16 0x00007f119f0d0444 in WebCore::ScriptElement::prepareScript (this=0x20843b8, scriptStartPosition=..., supportLegacyTypes=WebCore::ScriptElement::DisallowLegacyTypeInTypeAttribute) at ../../Source/WebCore/dom/ScriptElement.cpp:246
#17 0x00007f119f2deee1 in WebCore::HTMLScriptRunner::runScript (this=0x1c3e7e0, script=0x2084350, scriptStartPosition=...) at ../../Source/WebCore/html/parser/HTMLScriptRunner.cpp:312
#18 0x00007f119f2de678 in WebCore::HTMLScriptRunner::execute (this=0x1c3e7e0, scriptElement=..., scriptStartPosition=...) at ../../Source/WebCore/html/parser/HTMLScriptRunner.cpp:181
#19 0x00007f119f2c9a0f in WebCore::HTMLDocumentParser::runScriptsForPausedTreeBuilder (this=0x1c3dac0) at ../../Source/WebCore/html/parser/HTMLDocumentParser.cpp:271
#20 0x00007f119f2c9afa in WebCore::HTMLDocumentParser::canTakeNextToken (this=0x1c3dac0, mode=WebCore::HTMLDocumentParser::AllowYield, session=...) at ../../Source/WebCore/html/parser/HTMLDocumentParser.cpp:290
#21 0x00007f119f2ca11c in WebCore::HTMLDocumentParser::pumpTokenizer (this=0x1c3dac0, mode=WebCore::HTMLDocumentParser::AllowYield) at ../../Source/WebCore/html/parser/HTMLDocumentParser.cpp:535
#22 0x00007f119f2c9906 in WebCore::HTMLDocumentParser::resumeParsingAfterYield (this=0x1c3dac0) at ../../Source/WebCore/html/parser/HTMLDocumentParser.cpp:259
#23 0x00007f119f2dae44 in WebCore::HTMLParserScheduler::continueNextChunkTimerFired (this=0x1c3e970, timer=0x1c3e988) at ../../Source/WebCore/html/parser/HTMLParserScheduler.cpp:124
#24 0x00007f119f2db313 in WebCore::Timer&lt;WebCore::HTMLParserScheduler&gt;::fired (this=0x1c3e988) at ../../Source/WebCore/platform/Timer.h:114
#25 0x00007f11a027c7b7 in WebCore::ThreadTimers::sharedTimerFiredInternal (this=0x1ac5090) at ../../Source/WebCore/platform/ThreadTimers.cpp:129
#26 0x00007f11a027c6a7 in WebCore::ThreadTimers::sharedTimerFired () at ../../Source/WebCore/platform/ThreadTimers.cpp:105
#27 0x00007f11a0297357 in WebCore::timeout_cb () at ../../Source/WebCore/platform/gtk/SharedTimerGtk.cpp:49
#28 0x00007f119b77b4c3 in g_timeout_dispatch (source=0x1b34e90, source@entry=0xffff000000000002, callback=&lt;optimized out&gt;, user_data=&lt;optimized out&gt;) at gmain.c:4413
#29 0x00007f119b77a966 in g_main_dispatch (context=0x1811660) at gmain.c:3054
#30 g_main_context_dispatch (context=context@entry=0x1811660) at gmain.c:3630
#31 0x00007f119b77acb8 in g_main_context_iterate (context=0x1811660, block=block@entry=1, dispatch=dispatch@entry=1, self=&lt;optimized out&gt;) at gmain.c:3701
#32 0x00007f119b77b0ba in g_main_loop_run (loop=0x182d2b0) at gmain.c:3895
#33 0x00007f11a0295b96 in WebCore::RunLoop::run () at ../../Source/WebCore/platform/gtk/RunLoopGtk.cpp:61
#34 0x00007f119ebe6aff in WebKit::WebProcessMainGtk (argc=2, argv=0x7fffcae35668) at ../../Source/WebKit2/WebProcess/gtk/WebProcessMainGtk.cpp:78
#35 0x000000000040096d in main (argc=2, argv=0x7fffcae35668) at ../../Source/WebKit2/gtk/MainGtk.cpp:31
(gdb)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>954754</commentid>
    <comment_count>8</comment_count>
    <who name="Andres Gomez Garcia">agomez</who>
    <bug_when>2013-11-28 09:14:41 -0800</bug_when>
    <thetext>The executed JS crashing code seems to be this one:

&lt;script type=&quot;text/javascript&quot;&gt;
&lt;!--//

function buyItem(element, type, code, formatTitle) {
	$(&apos;#order-summary&apos;).load(
		&apos;http://www.pressure.co.uk/store/add/&apos;+type+&apos;/&apos;+code+&apos;/&apos;);
	$(&apos;#&apos;+element).addClass(&apos;bought&apos;);
}

$(&apos;a.buy-tip&apos;).each(function() {
	$(this).qtip({
		content: $(this).attr(&apos;name&apos;)+&apos; was added to your order&lt;br /&gt;&lt;a href=&quot;https://www.pressure.co.uk/store/view-order/&quot;&gt;View order&lt;/a&gt;&apos;,
		position: {
			at: &quot;bottom center&quot;,
			my: &quot;top center&quot;
		},
		show: {
			event: &apos;click&apos;,
			solo: true,
			delay: 0
		},
		hide: {	
			fixed: true,
			delay: 1000,
			effect: true,
			event: &quot;mouseleave&quot;
		},
		style: {
			tip: {
				corner: &quot;topMiddle&quot;,
				width: 12,
				height: 6
			},
			classes: &quot;ui-tooltip-ps&quot;
		}
	});
});
//--&gt;
&lt;/script&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>954911</commentid>
    <comment_count>9</comment_count>
    <who name="Alberto Garcia">berto</who>
    <bug_when>2013-11-29 02:01:59 -0800</bug_when>
    <thetext>(In reply to comment #8)
&gt; The executed JS crashing code seems to be this one:
  [...]

This is supposed to working in master, so there should be a commit
fixing it. I don&apos;t know if it rings a bell, Carlos?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>955288</commentid>
    <comment_count>10</comment_count>
    <who name="Andres Gomez Garcia">agomez</who>
    <bug_when>2013-12-02 01:39:23 -0800</bug_when>
    <thetext>I&apos;ve bisected the problem and this commits is fixing it:
https://trac.webkit.org/changeset/155201

I suppose it is worth integrating it in the webkit branch. Added proposal to:
https://trac.webkit.org/wiki/WebKitGTK/2.2.x

Maybe it is worth reassigning to Carlos García Campos.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>955293</commentid>
    <comment_count>11</comment_count>
    <who name="Carlos Garcia Campos">cgarcia</who>
    <bug_when>2013-12-02 02:01:30 -0800</bug_when>
    <thetext>Merged in the stable branch, thank you guys for reporting and bisecting.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>955313</commentid>
    <comment_count>12</comment_count>
    <who name="Alberto Garcia">berto</who>
    <bug_when>2013-12-02 03:06:49 -0800</bug_when>
    <thetext>(In reply to comment #10)
&gt; I&apos;ve bisected the problem and this commits is fixing it:
&gt; https://trac.webkit.org/changeset/155201

Awesome, thanks!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>955373</commentid>
    <comment_count>13</comment_count>
    <who name="Andres Gomez Garcia">agomez</who>
    <bug_when>2013-12-02 07:29:31 -0800</bug_when>
    <thetext>(In reply to comment #11)
&gt; Merged in the stable branch, thank you guys for reporting and bisecting.

Thank you for taking the time integrating!

(In reply to comment #12)
&gt; (In reply to comment #10)
&gt; &gt; I&apos;ve bisected the problem and this commits is fixing it:
&gt; &gt; https://trac.webkit.org/changeset/155201
&gt; 
&gt; Awesome, thanks!

Thanks to you for reporting! :)</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>