<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>15839</bug_id>
          
          <creation_ts>2007-11-04 22:17:45 -0800</creation_ts>
          <short_desc>fast/dom/xmlhttprequest-html-response-encoding.html crashes in PCRE under GuardMalloc</short_desc>
          <delta_ts>2007-12-03 02:23:09 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>JavaScriptCore</component>
          <version>523.x (Safari 3)</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.4</op_sys>
          <bug_status>VERIFIED</bug_status>
          <resolution>WORKSFORME</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>HasReduction, InRadar</keywords>
          <priority>P1</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Alexey Proskuryakov">ap</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>eric</cc>
    
    <cc>mitz</cc>
    
    <cc>mrowe</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>60274</commentid>
    <comment_count>0</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2007-11-04 22:17:45 -0800</bug_when>
    <thetext>run-webkit-tests -g fast/dom/xmlhttprequest-html-response-encoding.html

Thread 0 Crashed:
0   com.apple.JavaScriptCore 	0x0028037c jsRegExpCompile + 1744 (pcre_compile.c:2793)
1   com.apple.JavaScriptCore 	0x00218b78 KJS::RegExp::RegExp[in-charge](KJS::UString const&amp;, int) + 216 (regexp.cpp:46)
2   com.apple.JavaScriptCore 	0x002490e4 KJS::RegExpObjectImp::construct(KJS::ExecState*, KJS::List const&amp;) + 784 (regexp_object.cpp:443)
3   com.apple.JavaScriptCore 	0x002369f4 KJS::RegExpNode::evaluate(KJS::ExecState*) + 192 (nodes.cpp:390)
4   com.apple.JavaScriptCore 	0x00241a90 KJS::ArgumentListNode::evaluateList(KJS::ExecState*, KJS::List&amp;) + 100 (nodes.cpp:623)
...</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>60275</commentid>
    <comment_count>1</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2007-11-04 22:24:50 -0800</bug_when>
    <thetext>This looks like a logic error in jsRegExpCompile; I&apos;m wondering if it&apos;s been fixed in upstream PCRE already.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>60277</commentid>
    <comment_count>2</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2007-11-04 22:42:14 -0800</bug_when>
    <thetext>At a second glance, I think it&apos;s PCRE expecting a null-terminated string - we&apos;ve stopped doing that in bug 11849.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>62262</commentid>
    <comment_count>3</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2007-11-25 00:03:00 -0800</bug_when>
    <thetext>*** Bug 16127 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>62263</commentid>
    <comment_count>4</comment_count>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2007-11-25 00:08:27 -0800</bug_when>
    <thetext>I can look at this once I finally land all my PCRE cleanup changes.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>62409</commentid>
    <comment_count>5</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2007-11-26 16:26:02 -0800</bug_when>
    <thetext>&lt;rdar://problem/5611792&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>62782</commentid>
    <comment_count>6</comment_count>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2007-11-30 04:44:53 -0800</bug_when>
    <thetext>I can&apos;t reproduce this on TOT.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>63109</commentid>
    <comment_count>7</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2007-12-03 02:23:09 -0800</bug_when>
    <thetext>Neither can I.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>