<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>151279</bug_id>
          
          <creation_ts>2015-11-13 16:11:18 -0800</creation_ts>
          <short_desc>REGRESSION (r190370): CrashTracer: [USER] com.apple.WebKit.WebContent at com.apple.JavaScriptCore: JSC::JITCode::execute + 158</short_desc>
          <delta_ts>2015-11-14 13:13:07 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>JavaScriptCore</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Michael Saboff">msaboff</reporter>
          <assigned_to name="Michael Saboff">msaboff</assigned_to>
          <cc>benjamin</cc>
    
    <cc>commit-queue</cc>
    
    <cc>fpizlo</cc>
    
    <cc>ggaren</cc>
    
    <cc>keith_miller</cc>
    
    <cc>mark.lam</cc>
    
    <cc>saam</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1141971</commentid>
    <comment_count>0</comment_count>
    <who name="Michael Saboff">msaboff</who>
    <bug_when>2015-11-13 16:11:18 -0800</bug_when>
    <thetext>We are crashing loading airbnb.com with a back trace like:

&gt;  1 com.apple.JavaScriptCore       0x7fff8ce0c7ee JSC::JITCode::execute(JSC::VM*, JSC::ProtoCallFrame*) + 0x9e
   2 com.apple.JavaScriptCore       0x7fff8c92616b JSC::Interpreter::executeCall(JSC::ExecState*, JSC::JSObject*, JSC::CallType, JSC::CallData const&amp;, JSC::JSValue, JSC::ArgList const&amp;) + 0x1bb
   3 com.apple.JavaScriptCore       0x7fff8c925f9e JSC::call(JSC::ExecState*, JSC::JSValue, JSC::CallType, JSC::CallData const&amp;, JSC::JSValue, JSC::ArgList const&amp;) + 0x3e
   4 com.apple.JavaScriptCore       0x7fff8ca569da JSC::boundFunctionCall(JSC::ExecState*) + 0x27a
   5                                0x00003851da001028 0 + 61924200943656
   6 com.apple.JavaScriptCore       0x7fff8cf12941 llint_entry + 0x5ae9
   7 com.apple.JavaScriptCore       0x7fff8cf12941 llint_entry + 0x5ae9
   8 com.apple.JavaScriptCore       0x7fff8cf12941 llint_entry + 0x5ae9
   9 com.apple.JavaScriptCore       0x7fff8cf12941 llint_entry + 0x5ae9
  10 com.apple.JavaScriptCore       0x7fff8cf12941 llint_entry + 0x5ae9
...

&lt;rdar://problem/23484769&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1142051</commentid>
    <comment_count>1</comment_count>
      <attachid>265542</attachid>
    <who name="Michael Saboff">msaboff</who>
    <bug_when>2015-11-14 09:16:48 -0800</bug_when>
    <thetext>Created attachment 265542
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1142065</commentid>
    <comment_count>2</comment_count>
      <attachid>265542</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2015-11-14 13:13:04 -0800</bug_when>
    <thetext>Comment on attachment 265542
Patch

Clearing flags on attachment: 265542

Committed r192457: &lt;http://trac.webkit.org/changeset/192457&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1142066</commentid>
    <comment_count>3</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2015-11-14 13:13:07 -0800</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>265542</attachid>
            <date>2015-11-14 09:16:48 -0800</date>
            <delta_ts>2015-11-14 13:13:04 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>151279.patch</filename>
            <type>text/plain</type>
            <size>5250</size>
            <attacher name="Michael Saboff">msaboff</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9DaGFuZ2VMb2cKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkocmV2aXNpb24gMTkyNDU2KQorKysgU291cmNl
L0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE2IEBA
CisyMDE1LTExLTE0ICBNaWNoYWVsIFNhYm9mZiAgPG1zYWJvZmZAYXBwbGUuY29tPgorCisgICAg
ICAgIFJFR1JFU1NJT04gKHIxOTAzNzApOiBDcmFzaFRyYWNlcjogW1VTRVJdIGNvbS5hcHBsZS5X
ZWJLaXQuV2ViQ29udGVudCBhdCBjb20uYXBwbGUuSmF2YVNjcmlwdENvcmU6IEpTQzo6SklUQ29k
ZTo6ZXhlY3V0ZSArIDE1OAorICAgICAgICBodHRwczovL2J1Z3Mud2Via2l0Lm9yZy9zaG93X2J1
Zy5jZ2k/aWQ9MTUxMjc5CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisK
KyAgICAgICAgV2UgbmVlZCB0byByZXN0b3JlIGNhbGxlZSBzYXZlcyBldmVuIHdoZW4gd2UgdGFr
ZSB0aGUgc2xvdyBwYXRoIGluIGEgcG9seW1vcnBoaWMgY2FsbCBzdHViLgorICAgICAgICBNb3Zl
IHRoZSByZXN0b3JhdGlvbiB0byB0aGUgdG9wIG9mIHRoZSBzdHViIHNvIHRoYXQgaXQgaXMgZG9u
ZSBmb3IgYWxsIHBhdGhzLgorCisgICAgICAgICogaml0L1JlcGF0Y2guY3BwOgorICAgICAgICAo
SlNDOjpsaW5rUG9seW1vcnBoaWNDYWxsKToKKwogMjAxNS0xMS0xMyAgQ29tbWl0IFF1ZXVlICA8
Y29tbWl0LXF1ZXVlQHdlYmtpdC5vcmc+CiAKICAgICAgICAgVW5yZXZpZXdlZCwgcm9sbGluZyBv
dXQgcjE5MjQxNiBhbmQgcjE5MjQ0My4KSW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9qaXQv
UmVwYXRjaC5jcHAKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291cmNlL0phdmFTY3JpcHRDb3JlL2ppdC9SZXBh
dGNoLmNwcAkocmV2aXNpb24gMTkyMTY4KQorKysgU291cmNlL0phdmFTY3JpcHRDb3JlL2ppdC9S
ZXBhdGNoLmNwcAkod29ya2luZyBjb3B5KQpAQCAtODAwLDcgKzgwMCw4IEBAIHZvaWQgbGlua1Bv
bHltb3JwaGljQ2FsbCgKICAgICAgICAgICAgIEFzc2VtYmx5SGVscGVyczo6c2VsZWN0U2NyYXRj
aEdQUihjYWxsZWVHUFIsIGNvbXBhcmlzb25WYWx1ZUdQUiwgR1BSSW5mbzo6cmVnVDMpOwogICAg
IH0KICAgICBzdHViSml0Lm1vdmUoQ0NhbGxIZWxwZXJzOjpUcnVzdGVkSW1tUHRyKGZhc3RDb3Vu
dHMuZ2V0KCkpLCBmYXN0Q291bnRzQmFzZUdQUik7Ci0gICAgCisgICAgaWYgKCFmcmFtZVNodWZm
bGVyICYmIGNhbGxMaW5rSW5mby5pc1RhaWxDYWxsKCkpCisgICAgICAgIHN0dWJKaXQuZW1pdFJl
c3RvcmVDYWxsZWVTYXZlcygpOwogICAgIEJpbmFyeVN3aXRjaCBiaW5hcnlTd2l0Y2goY29tcGFy
aXNvblZhbHVlR1BSLCBjYXNlVmFsdWVzLCBCaW5hcnlTd2l0Y2g6OkludFB0cik7CiAgICAgQ0Nh
bGxIZWxwZXJzOjpKdW1wTGlzdCBkb25lOwogICAgIHdoaWxlIChiaW5hcnlTd2l0Y2guYWR2YW5j
ZShzdHViSml0KSkgewpAQCAtODIxLDcgKzgyMiw2IEBAIHZvaWQgbGlua1BvbHltb3JwaGljQ2Fs
bCgKICAgICAgICAgICAgIENhbGxGcmFtZVNodWZmbGVyKHN0dWJKaXQsIGZyYW1lU2h1ZmZsZXIt
PnNuYXBzaG90KCkpLnByZXBhcmVGb3JUYWlsQ2FsbCgpOwogICAgICAgICAgICAgY2FsbHNbY2Fz
ZUluZGV4XS5jYWxsID0gc3R1YkppdC5uZWFyVGFpbENhbGwoKTsKICAgICAgICAgfSBlbHNlIGlm
IChjYWxsTGlua0luZm8uaXNUYWlsQ2FsbCgpKSB7Ci0gICAgICAgICAgICBzdHViSml0LmVtaXRS
ZXN0b3JlQ2FsbGVlU2F2ZXMoKTsKICAgICAgICAgICAgIHN0dWJKaXQucHJlcGFyZUZvclRhaWxD
YWxsU2xvdygpOwogICAgICAgICAgICAgY2FsbHNbY2FzZUluZGV4XS5jYWxsID0gc3R1YkppdC5u
ZWFyVGFpbENhbGwoKTsKICAgICAgICAgfSBlbHNlCkluZGV4OiBMYXlvdXRUZXN0cy9DaGFuZ2VM
b2cKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PQotLS0gTGF5b3V0VGVzdHMvQ2hhbmdlTG9nCShyZXZpc2lvbiAxOTIxNjgp
CisrKyBMYXlvdXRUZXN0cy9DaGFuZ2VMb2cJKHdvcmtpbmcgY29weSkKQEAgLTEsMyArMSwxNiBA
QAorMjAxNS0xMS0xNCAgTWljaGFlbCBTYWJvZmYgIDxtc2Fib2ZmQGFwcGxlLmNvbT4KKworICAg
ICAgICBSRUdSRVNTSU9OIChyMTkwMzcwKTogQ3Jhc2hUcmFjZXI6IFtVU0VSXSBjb20uYXBwbGUu
V2ViS2l0LldlYkNvbnRlbnQgYXQgY29tLmFwcGxlLkphdmFTY3JpcHRDb3JlOiBKU0M6OkpJVENv
ZGU6OmV4ZWN1dGUgKyAxNTgKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19i
dWcuY2dpP2lkPTE1MTI3OQorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgor
CisgICAgICAgIE5ldyByZWdyZXNzaW9uIHRlc3QuCisKKyAgICAgICAgKiBqcy9yZWdyZXNzLTE1
MTI3OS1leHBlY3RlZC50eHQ6IEFkZGVkLgorICAgICAgICAqIGpzL3JlZ3Jlc3MtMTUxMjc5Lmh0
bWw6IEFkZGVkLgorICAgICAgICAqIGpzL3NjcmlwdC10ZXN0cy9yZWdyZXNzLTE1MTI3OS5qczog
QWRkZWQuCisKIDIwMTUtMTEtMDkgIFNhaWQgQWJvdS1IYWxsYXdhICA8c2Fib3VoYWxsYXdhQGFw
cGxlLmNvbT4KIAogICAgICAgICBSRUdSRVNTSU9OIChyMTkwODgzKTogRXJyb3IgY2FsY3VsYXRp
bmcgdGhlIHRpbGUgc2l6ZSBmb3IgYW4gU1ZHIHdpdGggbm8gaW50cmluc2ljIHNpemUgYnV0IHdp
dGggbGFyZ2UgZmxvYXRpbmcgaW50cmluc2ljIHJhdGlvCkluZGV4OiBMYXlvdXRUZXN0cy9qcy9y
ZWdyZXNzLTE1MTI3OS1leHBlY3RlZC50eHQKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gTGF5b3V0VGVzdHMvanMv
cmVncmVzcy0xNTEyNzktZXhwZWN0ZWQudHh0CShyZXZpc2lvbiAwKQorKysgTGF5b3V0VGVzdHMv
anMvcmVncmVzcy0xNTEyNzktZXhwZWN0ZWQudHh0CSh3b3JraW5nIGNvcHkpCkBAIC0wLDAgKzEs
MTAgQEAKK1JlZ3Jlc3Npb24gdGVzdCBmb3IgaHR0cHM6Ly93ZWJraXQub3JnL2IvMTUxMjc5Lgor
CitPbiBzdWNjZXNzLCB5b3Ugd2lsbCBzZWUgYSBzZXJpZXMgb2YgIlBBU1MiIG1lc3NhZ2VzLCBm
b2xsb3dlZCBieSAiVEVTVCBDT01QTEVURSIuCisKKworUEFTUyBQcm9wZXJseSBoYW5kbGVkIG1l
Z2Ftb3JwaGljIHRhaWwgY2FsbCBmcm9tIGEgSlMgZW50cnkgZnVuY3Rpb24KK1BBU1Mgc3VjY2Vz
c2Z1bGx5UGFyc2VkIGlzIHRydWUKKworVEVTVCBDT01QTEVURQorCkluZGV4OiBMYXlvdXRUZXN0
cy9qcy9yZWdyZXNzLTE1MTI3OS5odG1sCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIExheW91dFRlc3RzL2pzL3Jl
Z3Jlc3MtMTUxMjc5Lmh0bWwJKHJldmlzaW9uIDApCisrKyBMYXlvdXRUZXN0cy9qcy9yZWdyZXNz
LTE1MTI3OS5odG1sCSh3b3JraW5nIGNvcHkpCkBAIC0wLDAgKzEsMTAgQEAKKzwhRE9DVFlQRSBI
VE1MIFBVQkxJQyAiLS8vSUVURi8vRFREIEhUTUwvL0VOIj4KKzxodG1sPgorPGhlYWQ+Cis8c2Ny
aXB0IHNyYz0iLi4vcmVzb3VyY2VzL2pzLXRlc3QtcHJlLmpzIj48L3NjcmlwdD4KKzwvaGVhZD4K
Kzxib2R5PgorPHNjcmlwdCBzcmM9InNjcmlwdC10ZXN0cy9yZWdyZXNzLTE1MTI3OS5qcyI+PC9z
Y3JpcHQ+Cis8c2NyaXB0IHNyYz0iLi4vcmVzb3VyY2VzL2pzLXRlc3QtcG9zdC5qcyI+PC9zY3Jp
cHQ+Cis8L2JvZHk+Cis8L2h0bWw+CkluZGV4OiBMYXlvdXRUZXN0cy9qcy9zY3JpcHQtdGVzdHMv
cmVncmVzcy0xNTEyNzkuanMKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gTGF5b3V0VGVzdHMvanMvc2NyaXB0LXRl
c3RzL3JlZ3Jlc3MtMTUxMjc5LmpzCShyZXZpc2lvbiAwKQorKysgTGF5b3V0VGVzdHMvanMvc2Ny
aXB0LXRlc3RzL3JlZ3Jlc3MtMTUxMjc5LmpzCSh3b3JraW5nIGNvcHkpCkBAIC0wLDAgKzEsNDIg
QEAKK2Rlc2NyaXB0aW9uKCJSZWdyZXNzaW9uIHRlc3QgZm9yIGh0dHBzOi8vd2Via2l0Lm9yZy9i
LzE1MTI3OS4iKTsKKworLy8gVGhpcyB0ZXN0IHZlcmlmaWVzIHRoYXQgYSBtZWdhbW9ycGhpYyB0
YWlsIGNhbGwgZnJvbSB0aGUgZmlyc3QgY2FsbGVlIGZyb20gQysrIGNvZGUKKy8vIHdvcmtzIHdp
dGhvdXQgY3Jhc2hpbmcuCisKK2Z1bmN0aW9uIGJhcigpIHsKKyAgICByZXR1cm4gMTE7Cit9CisK
K25vSW5saW5lKGJhcik7CisKK2Z1bmN0aW9uIGZvbyh0aGlzQXJndW1lbnQpCit7CisgICAgInVz
ZSBzdHJpY3QiOworCisgICAgcmV0dXJuIHRoaXMuY2FsbCguLi5hcmd1bWVudHMpOworfQorCit2
YXIgZml4ZWREYXRlID0gbmV3IERhdGUoMjAxMSwgMTEsIDExLCAxMSwgMTEsIDExKTsKK3ZhciBi
b3VuZEZ1bmNzID0gW107CisKK2JvdW5kRnVuY3NbMF0gPSBmb28uYmluZChEYXRlLnByb3RvdHlw
ZS5nZXRTZWNvbmRzLCBmaXhlZERhdGUpOworYm91bmRGdW5jc1sxXSA9IGZvby5iaW5kKERhdGUu
cHJvdG90eXBlLmdldE1pbnV0ZXMsIGZpeGVkRGF0ZSk7Citib3VuZEZ1bmNzWzJdID0gZm9vLmJp
bmQoRGF0ZS5wcm90b3R5cGUuZ2V0SG91cnMsIGZpeGVkRGF0ZSk7Citib3VuZEZ1bmNzWzNdID0g
Zm9vLmJpbmQoRGF0ZS5wcm90b3R5cGUuZ2V0RGF0ZSwgZml4ZWREYXRlKTsKK2JvdW5kRnVuY3Nb
NF0gPSBmb28uYmluZChEYXRlLnByb3RvdHlwZS5nZXRNb250aCwgZml4ZWREYXRlKTsKK2JvdW5k
RnVuY3NbNV0gPSBmb28uYmluZChiYXIsIDApOworCitmdW5jdGlvbiB0ZXN0KCkKK3sKKyAgICBm
b3IgKHZhciBpID0gMDsgaSA8IDIwMDAwMDsgaSsrKSB7CisgICAgICAgIGdvdCA9IGJvdW5kRnVu
Y3NbaSAlIDZdKCk7CisgICAgICAgIGlmIChnb3QgIT0gMTEpCisgICAgICAgICAgICB0ZXN0RmFp
bGVkKCJGdW5jdGlvbiByZXR1cm5lZCAiICsgZ290ICsgIiBidXQgZXhwZWN0ZWQgMTEhIik7Cisg
ICAgfQorfQorCitub0lubGluZSh0ZXN0KTsKKwordGVzdCgpOworCit0ZXN0UGFzc2VkKCJQcm9w
ZXJseSBoYW5kbGVkIG1lZ2Ftb3JwaGljIHRhaWwgY2FsbCBmcm9tIGEgSlMgZW50cnkgZnVuY3Rp
b24iKTsK
</data>

          </attachment>
      

    </bug>

</bugzilla>