<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>17313</bug_id>
          
          <creation_ts>2008-02-11 14:07:59 -0800</creation_ts>
          <short_desc>querySelectorAll() causing crashes when called via dojo.query() wrapper</short_desc>
          <delta_ts>2008-05-17 02:29:48 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>DOM</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://dojotoolkit.org/~alex/anon_view/dojo/tests/_base/query.html</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P1</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>13846</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="Alex Russell">alex</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>ap</cc>
    
    <cc>catfish.man</cc>
    
    <cc>dylans</cc>
    
    <cc>hyatt</cc>
    
    <cc>mitz</cc>
    
    <cc>mrowe</cc>
    
    <cc>sam</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>70317</commentid>
    <comment_count>0</comment_count>
    <who name="Alex Russell">alex</who>
    <bug_when>2008-02-11 14:07:59 -0800</bug_when>
    <thetext>Individual calls to document.querySelectorAll(), and individual calls to [node].querySelectorAll() work as expected, but when being wrapped by dojo.query() (and called many times in succession), we are seeing crashes on the latest webkit nightlies.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70323</commentid>
    <comment_count>1</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2008-02-11 14:52:40 -0800</bug_when>
    <thetext>FWIW, I could not reproduce this by opening the bug URL with a local debug build of r30153.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70325</commentid>
    <comment_count>2</comment_count>
    <who name="Alex Russell">alex</who>
    <bug_when>2008-02-11 15:04:11 -0800</bug_when>
    <thetext>The nightly I&apos;m working from is r30123...I&apos;ll try again on tomorrow&apos;s build.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70348</commentid>
    <comment_count>3</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-02-11 19:08:09 -0800</bug_when>
    <thetext>Can you please attach the crash logs from this crash?  See &lt;http://webkit.org/quality/crashlogs.html&gt; for details.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70475</commentid>
    <comment_count>4</comment_count>
    <who name="Dylan Schiemann">dylans</who>
    <bug_when>2008-02-12 21:00:18 -0800</bug_when>
    <thetext>(In reply to comment #3)
&gt; Can you please attach the crash logs from this crash?  See
&gt; &lt;http://webkit.org/quality/crashlogs.html&gt; for details.
&gt; 

Date/Time:      2008-02-12 20:58:59.020 -0800
OS Version:     10.4.11 (Build 8S2167)
Report Version: 4

Command: Safari
Path:    /Applications/Safari.app/Contents/MacOS/Safari
Parent:  WindowServer [87]

Version: r30153 (30153)

PID:    6917
Thread: 0

Exception:  EXC_BAD_ACCESS (0x0001)
Codes:      KERN_INVALID_ADDRESS (0x0001) at 0x898c45bf

Thread 0 Crashed:
0   com.apple.WebCore        	0x014d0e6b WebCore::TextIterator::handleTextBox() + 587
1   com.apple.WebCore        	0x014d20e6 WebCore::TextIterator::advance() + 54
2   com.apple.WebCore        	0x014d25db WebCore::plainTextToMallocAllocatedBuffer(WebCore::Range const*, unsigned&amp;) + 187
3   com.apple.WebCore        	0x014eca12 -[WebCoreFrameBridge stringForRange:] + 50
4   com.apple.WebKit         	0x00346e44 -[WebHTMLView(WebDocumentPrivateProtocols) string] + 84
5   com.apple.Safari         	0x0002fbf9 0x1000 + 191481
6   com.apple.Safari         	0x0002f7d8 0x1000 + 190424
7   com.apple.Safari         	0x0002f5ec 0x1000 + 189932
8   com.apple.Safari         	0x0002f4e7 0x1000 + 189671
9   com.apple.Foundation     	0x9283f2be __NSFireTimer + 199
10  com.apple.CoreFoundation 	0x9082d76a CFRunLoopRunSpecific + 3341
11  com.apple.CoreFoundation 	0x9082ca56 CFRunLoopRunInMode + 61
12  com.apple.HIToolbox      	0x92df0878 RunCurrentEventLoopInMode + 285
13  com.apple.HIToolbox      	0x92deff82 ReceiveNextEventCommon + 385
14  com.apple.HIToolbox      	0x92defdd9 BlockUntilNextEventMatchingListInMode + 81
15  com.apple.AppKit         	0x93296485 _DPSNextEvent + 572
16  com.apple.AppKit         	0x93296076 -[NSApplication nextEventMatchingMask:untilDate:inMode:dequeue:] + 137
17  com.apple.Safari         	0x00009208 0x1000 + 33288
18  com.apple.AppKit         	0x9328fdfb -[NSApplication run] + 512
19  com.apple.AppKit         	0x93283d4f NSApplicationMain + 573
20  com.apple.Safari         	0x00090652 0x1000 + 587346
21  com.apple.Safari         	0x000027a9 0x1000 + 6057

Thread 1:
0   libSystem.B.dylib        	0x90009cd7 mach_msg_trap + 7
1   com.unsanity.ape         	0xc0001cac __ape_agent + 307
2   libSystem.B.dylib        	0x90024227 _pthread_body + 84

Thread 2:
0   libSystem.B.dylib        	0x900248c7 semaphore_wait_signal_trap + 7
1   com.apple.WebCore        	0x01200b0f WebCore::IconDatabase::syncThreadMainLoop() + 239
2   com.apple.WebCore        	0x01200c25 WebCore::IconDatabase::iconDatabaseSyncThread() + 181
3   libSystem.B.dylib        	0x90024227 _pthread_body + 84

Thread 3:
0   libSystem.B.dylib        	0x90009cd7 mach_msg_trap + 7
1   com.apple.CoreFoundation 	0x9082d23b CFRunLoopRunSpecific + 2014
2   com.apple.CoreFoundation 	0x9082ca56 CFRunLoopRunInMode + 61
3   com.apple.Foundation     	0x92854bca +[NSURLCache _diskCacheSyncLoop:] + 206
4   com.apple.Foundation     	0x927f82c0 forkThreadForFunction + 123
5   libSystem.B.dylib        	0x90024227 _pthread_body + 84

Thread 4:
0   libSystem.B.dylib        	0x90009cd7 mach_msg_trap + 7
1   com.apple.CoreFoundation 	0x9082d23b CFRunLoopRunSpecific + 2014
2   com.apple.CoreFoundation 	0x9082ca56 CFRunLoopRunInMode + 61
3   com.apple.Foundation     	0x9282d9ef +[NSURLConnection(NSURLConnectionInternal) _resourceLoadLoop:] + 259
4   com.apple.Foundation     	0x927f82c0 forkThreadForFunction + 123
5   libSystem.B.dylib        	0x90024227 _pthread_body + 84

Thread 5:
0   libSystem.B.dylib        	0x900248c7 semaphore_wait_signal_trap + 7
1   com.apple.Foundation     	0x9284e250 -[NSConditionLock lockWhenCondition:] + 39
2   com.apple.Syndication    	0x9ad79966 -[AsyncDB _run:] + 181
3   com.apple.Foundation     	0x927f82c0 forkThreadForFunction + 123
4   libSystem.B.dylib        	0x90024227 _pthread_body + 84

Thread 6:
0   libSystem.B.dylib        	0x9001a1cc select + 12
1   libSystem.B.dylib        	0x90024227 _pthread_body + 84

Thread 0 crashed with X86 Thread State (32-bit):
  eax: 0x458c3dd5  ebx: 0x014ec9ea  ecx: 0x898c458b  edx: 0x898c458b
  edi: 0xbfffeb74  esi: 0x898c458b  ebp: 0xbfffeae8  esp: 0xbfffea80
   ss: 0x0000001f  efl: 0x00010286  eip: 0x014d0e6b   cs: 0x00000017
   ds: 0x0000001f   es: 0x0000001f   fs: 0x00000000   gs: 0x00000037

Binary Images Description:
    0x1000 -   0x119fff com.apple.Safari 3.0.4 (523.12.2)	/Applications/Safari.app/Contents/MacOS/Safari
  0x155000 -   0x156fff WebKitNightlyEnabler.dylib 	/Applications/WebKit.app/Contents/Resources/WebKitNightlyEnabler.dylib
  0x305000 -   0x3c2fff com.apple.WebKit 525.8+	/Applications/WebKit.app/Contents/Frameworks/10.4/WebKit.framework/Versions/A/WebKit
  0x457000 -   0x526fff com.apple.JavaScriptCore 525.8+	/Applications/WebKit.app/Contents/Frameworks/10.4/JavaScriptCore.framework/Versions/A/JavaScriptCore
  0x5aa000 -   0x5abfff com.Logitech.Control Center.Scroll Enhancer 2.1.4	/Library/Application Enhancers/LCC Scroll Enhancer.ape/Contents/MacOS/LCC Scroll Enhancer
 0x1008000 -  0x1654fff com.apple.WebCore 525.8+	/Applications/WebKit.app/Contents/Frameworks/10.4/WebCore.framework/Versions/A/WebCore
0x270d3000 - 0x27140fff com.DivXInc.DivXDecoder 6.6.0	/Library/QuickTime/DivX Decoder.component/Contents/MacOS/DivX Decoder
0x8f8c0000 - 0x8f95ffff com.apple.QuickTimeImporters.component 7.4 (92)	/System/Library/QuickTime/QuickTimeImporters.component/Contents/MacOS/QuickTimeImporters
0x8fe00000 - 0x8fe4afff dyld 46.16	/usr/lib/dyld
0x90000000 - 0x90171fff libSystem.B.dylib 	/usr/lib/libSystem.B.dylib
0x901c1000 - 0x901c3fff libmathCommon.A.dylib 	/usr/lib/system/libmathCommon.A.dylib
0x901c5000 - 0x90202fff com.apple.CoreText 1.1.3 (???)	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreText.framework/Versions/A/CoreText
0x90229000 - 0x902fffff ATS 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ATS.framework/Versions/A/ATS
0x9031f000 - 0x90774fff com.apple.CoreGraphics 1.258.77 (???)	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/CoreGraphics
0x9080b000 - 0x908d3fff com.apple.CoreFoundation 6.4.9 (368.31)	/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
0x90911000 - 0x90911fff com.apple.CoreServices 10.4 (???)	/System/Library/Frameworks/CoreServices.framework/Versions/A/CoreServices
0x90913000 - 0x90a07fff libicucore.A.dylib 	/usr/lib/libicucore.A.dylib
0x90a57000 - 0x90ad6fff libobjc.A.dylib 	/usr/lib/libobjc.A.dylib
0x90aff000 - 0x90b63fff libstdc++.6.dylib 	/usr/lib/libstdc++.6.dylib
0x90bd2000 - 0x90bd9fff libgcc_s.1.dylib 	/usr/lib/libgcc_s.1.dylib
0x90bde000 - 0x90c51fff com.apple.framework.IOKit 1.4.8 (???)	/System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
0x90c66000 - 0x90c78fff libauto.dylib 	/usr/lib/libauto.dylib
0x90c7e000 - 0x90f24fff com.apple.CoreServices.CarbonCore 682.28	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/CarbonCore.framework/Versions/A/CarbonCore
0x90f67000 - 0x90fcffff com.apple.CoreServices.OSServices 4.1	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/OSServices.framework/Versions/A/OSServices
0x91008000 - 0x91047fff com.apple.CFNetwork 129.22	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/CFNetwork.framework/Versions/A/CFNetwork
0x9105a000 - 0x9106afff com.apple.WebServices 1.1.3 (1.1.0)	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/WebServicesCore.framework/Versions/A/WebServicesCore
0x91075000 - 0x910f4fff com.apple.SearchKit 1.0.7	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/SearchKit.framework/Versions/A/SearchKit
0x9112e000 - 0x9114cfff com.apple.Metadata 10.4.4 (121.36)	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/Metadata.framework/Versions/A/Metadata
0x91158000 - 0x91166fff libz.1.dylib 	/usr/lib/libz.1.dylib
0x91169000 - 0x91308fff com.apple.security 4.5.2 (29774)	/System/Library/Frameworks/Security.framework/Versions/A/Security
0x91406000 - 0x9140efff com.apple.DiskArbitration 2.1.2	/System/Library/Frameworks/DiskArbitration.framework/Versions/A/DiskArbitration
0x91415000 - 0x9141cfff libbsm.dylib 	/usr/lib/libbsm.dylib
0x91420000 - 0x91446fff com.apple.SystemConfiguration 1.8.6	/System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfiguration
0x91458000 - 0x914cefff com.apple.audio.CoreAudio 3.0.5	/System/Library/Frameworks/CoreAudio.framework/Versions/A/CoreAudio
0x9151f000 - 0x9151ffff com.apple.ApplicationServices 10.4 (???)	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/ApplicationServices
0x91521000 - 0x9154dfff com.apple.AE 314 (313)	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/AE.framework/Versions/A/AE
0x91560000 - 0x91634fff com.apple.ColorSync 4.4.10	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ColorSync.framework/Versions/A/ColorSync
0x9166f000 - 0x916e2fff com.apple.print.framework.PrintCore 4.6 (177.13)	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/PrintCore.framework/Versions/A/PrintCore
0x91710000 - 0x917b9fff com.apple.QD 3.10.25 (???)	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/QD.framework/Versions/A/QD
0x917df000 - 0x9182afff com.apple.HIServices 1.5.2 (???)	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/HIServices.framework/Versions/A/HIServices
0x91849000 - 0x9185ffff com.apple.LangAnalysis 1.6.3	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/LangAnalysis.framework/Versions/A/LangAnalysis
0x9186b000 - 0x91886fff com.apple.FindByContent 1.5	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/FindByContent.framework/Versions/A/FindByContent
0x91891000 - 0x918cefff com.apple.LaunchServices 182	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/LaunchServices
0x918e2000 - 0x918eefff com.apple.speech.synthesis.framework 3.5	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/SpeechSynthesis.framework/Versions/A/SpeechSynthesis
0x918f5000 - 0x91935fff com.apple.ImageIO.framework 1.5.6	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/ImageIO
0x91948000 - 0x919fafff libcrypto.0.9.7.dylib 	/usr/lib/libcrypto.0.9.7.dylib
0x91a40000 - 0x91a56fff libcups.2.dylib 	/usr/lib/libcups.2.dylib
0x91a5b000 - 0x91a79fff libJPEG.dylib 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libJPEG.dylib
0x91a7e000 - 0x91addfff libJP2.dylib 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libJP2.dylib
0x91aef000 - 0x91af3fff libGIF.dylib 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libGIF.dylib
0x91af5000 - 0x91b7dfff libRaw.dylib 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libRaw.dylib
0x91b81000 - 0x91bbefff libTIFF.dylib 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libTIFF.dylib
0x91bc4000 - 0x91bdefff libPng.dylib 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libPng.dylib
0x91be3000 - 0x91be5fff libRadiance.dylib 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libRadiance.dylib
0x91be7000 - 0x91cc5fff libxml2.2.dylib 	/usr/lib/libxml2.2.dylib
0x91ce2000 - 0x91ce2fff com.apple.Accelerate 1.3.1 (Accelerate 1.3.1)	/System/Library/Frameworks/Accelerate.framework/Versions/A/Accelerate
0x91ce4000 - 0x91d72fff com.apple.vImage 2.5	/System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vImage.framework/Versions/A/vImage
0x91d79000 - 0x91d79fff com.apple.Accelerate.vecLib 3.3.1 (vecLib 3.3.1)	/System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/vecLib
0x91d7b000 - 0x91dd4fff libvMisc.dylib 	/System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libvMisc.dylib
0x91ddd000 - 0x91e01fff libvDSP.dylib 	/System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libvDSP.dylib
0x91e09000 - 0x92212fff libBLAS.dylib 	/System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libBLAS.dylib
0x9224c000 - 0x92600fff libLAPACK.dylib 	/System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libLAPACK.dylib
0x9262d000 - 0x9271afff libiconv.2.dylib 	/usr/lib/libiconv.2.dylib
0x9271c000 - 0x9279afff com.apple.DesktopServices 1.3.7	/System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Versions/A/DesktopServicesPriv
0x927db000 - 0x92a0bfff com.apple.Foundation 6.4.9 (567.36)	/System/Library/Frameworks/Foundation.framework/Versions/C/Foundation
0x92b25000 - 0x92b3cfff libGL.dylib 	/System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGL.dylib
0x92b47000 - 0x92b9ffff libGLU.dylib 	/System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGLU.dylib
0x92bb3000 - 0x92bb3fff com.apple.Carbon 10.4 (???)	/System/Library/Frameworks/Carbon.framework/Versions/A/Carbon
0x92bb5000 - 0x92bc5fff com.apple.ImageCapture 3.0.4	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/ImageCapture.framework/Versions/A/ImageCapture
0x92bd4000 - 0x92bdcfff com.apple.speech.recognition.framework 3.6	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/SpeechRecognition.framework/Versions/A/SpeechRecognition
0x92be2000 - 0x92be8fff com.apple.securityhi 2.0.1 (24742)	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/SecurityHI.framework/Versions/A/SecurityHI
0x92bee000 - 0x92c7ffff com.apple.ink.framework 101.2.1 (71)	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Ink.framework/Versions/A/Ink
0x92c93000 - 0x92c97fff com.apple.help 1.0.3 (32.1)	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Help.framework/Versions/A/Help
0x92c9a000 - 0x92cb8fff com.apple.openscripting 1.2.5 (???)	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/OpenScripting.framework/Versions/A/OpenScripting
0x92cca000 - 0x92cd0fff com.apple.print.framework.Print 5.2 (192.4)	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Print.framework/Versions/A/Print
0x92cd6000 - 0x92d39fff com.apple.htmlrendering 66.1 (1.1.3)	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HTMLRendering.framework/Versions/A/HTMLRendering
0x92d60000 - 0x92da1fff com.apple.NavigationServices 3.4.4 (3.4.3)	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/NavigationServices.framework/Versions/A/NavigationServices
0x92dc8000 - 0x92dd6fff com.apple.audio.SoundManager 3.9.1	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/CarbonSound.framework/Versions/A/CarbonSound
0x92ddd000 - 0x92de2fff com.apple.CommonPanels 1.2.3 (73)	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/CommonPanels.framework/Versions/A/CommonPanels
0x92de7000 - 0x930dcfff com.apple.HIToolbox 1.4.10 (???)	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.framework/Versions/A/HIToolbox
0x931e2000 - 0x931edfff com.apple.opengl 1.4.16	/System/Library/Frameworks/OpenGL.framework/Versions/A/OpenGL
0x931f2000 - 0x9320dfff com.apple.DirectoryService.Framework 3.3	/System/Library/Frameworks/DirectoryService.framework/Versions/A/DirectoryService
0x9327d000 - 0x9327dfff com.apple.Cocoa 6.4 (???)	/System/Library/Frameworks/Cocoa.framework/Versions/A/Cocoa
0x9327f000 - 0x93935fff com.apple.AppKit 6.4.9 (824.44)	/System/Library/Frameworks/AppKit.framework/Versions/C/AppKit
0x93cb6000 - 0x93d31fff com.apple.CoreData 91 (92.1)	/System/Library/Frameworks/CoreData.framework/Versions/A/CoreData
0x93d6a000 - 0x93e23fff com.apple.audio.toolbox.AudioToolbox 1.4.7	/System/Library/Frameworks/AudioToolbox.framework/Versions/A/AudioToolbox
0x93e66000 - 0x93e66fff com.apple.audio.units.AudioUnit 1.4.3	/System/Library/Frameworks/AudioUnit.framework/Versions/A/AudioUnit
0x93e68000 - 0x94029fff com.apple.QuartzCore 1.4.12	/System/Library/Frameworks/QuartzCore.framework/Versions/A/QuartzCore
0x9406f000 - 0x940b0fff libsqlite3.0.dylib 	/usr/lib/libsqlite3.0.dylib
0x940b8000 - 0x940f2fff libGLImage.dylib 	/System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGLImage.dylib
0x940f7000 - 0x9410dfff com.apple.CoreVideo 1.4.2	/System/Library/Frameworks/CoreVideo.framework/Versions/A/CoreVideo
0x941a6000 - 0x941e4fff com.apple.vmutils 4.0.2 (93.1)	/System/Library/PrivateFrameworks/vmutils.framework/Versions/A/vmutils
0x94228000 - 0x94239fff com.apple.securityfoundation 2.2.1 (28150)	/System/Library/Frameworks/SecurityFoundation.framework/Versions/A/SecurityFoundation
0x94247000 - 0x94285fff com.apple.securityinterface 2.2.1 (27695)	/System/Library/Frameworks/SecurityInterface.framework/Versions/A/SecurityInterface
0x942a1000 - 0x942b0fff libCGATS.A.dylib 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libCGATS.A.dylib
0x942b7000 - 0x942c2fff libCSync.A.dylib 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libCSync.A.dylib
0x9430e000 - 0x94328fff libRIP.A.dylib 	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libRIP.A.dylib
0x9432e000 - 0x94645fff com.apple.QuickTime 7.4.0 (92)	/System/Library/Frameworks/QuickTime.framework/Versions/A/QuickTime
0x947ca000 - 0x94910fff com.apple.AddressBook.framework 4.0.6 (490)	/System/Library/Frameworks/AddressBook.framework/Versions/A/AddressBook
0x9499c000 - 0x949abfff com.apple.DSObjCWrappers.Framework 1.1	/System/Library/PrivateFrameworks/DSObjCWrappers.framework/Versions/A/DSObjCWrappers
0x949b2000 - 0x949dbfff com.apple.LDAPFramework 1.4.2 (69.1.1)	/System/Library/Frameworks/LDAP.framework/Versions/A/LDAP
0x949e1000 - 0x949f0fff libsasl2.2.dylib 	/usr/lib/libsasl2.2.dylib
0x949f4000 - 0x94a19fff libssl.0.9.7.dylib 	/usr/lib/libssl.0.9.7.dylib
0x94a25000 - 0x94a42fff libresolv.9.dylib 	/usr/lib/libresolv.9.dylib
0x96da2000 - 0x96da2fff com.apple.vecLib 3.3.1 (vecLib 3.3.1)	/System/Library/Frameworks/vecLib.framework/Versions/A/vecLib
0x97411000 - 0x97416fff com.apple.agl 2.5.9 (AGL-2.5.9)	/System/Library/Frameworks/AGL.framework/Versions/A/AGL
0x98e82000 - 0x99cc4fff com.apple.QuickTimeComponents.component 7.4 (92)	/System/Library/QuickTime/QuickTimeComponents.component/Contents/MacOS/QuickTimeComponents
0x9aa61000 - 0x9aa91fff com.apple.QuickTime Plugin.plugin 7.4 (92)	/Library/Internet Plug-Ins/QuickTime Plugin.plugin/Contents/MacOS/QuickTime Plugin
0x9ad77000 - 0x9adaefff com.apple.Syndication 1.0.7 (55)	/System/Library/PrivateFrameworks/Syndication.framework/Versions/A/Syndication
0x9adca000 - 0x9addcfff com.apple.SyndicationUI 1.0.7 (55)	/System/Library/PrivateFrameworks/SyndicationUI.framework/Versions/A/SyndicationUI
0xc0000000 - 0xc000efff com.unsanity.ape 2.0.2	/Library/Frameworks/ApplicationEnhancer.framework/Versions/A/ApplicationEnhancer

Model: MacPro1,1, BootROM MP11.005C.B08, 4 processors, Dual-Core Intel Xeon, 2.66 GHz, 8 GB
Graphics: NVIDIA GeForce 7300 GT, NVIDIA GeForce 7300 GT, PCIe, 256 MB
Graphics: NVIDIA GeForce 7300 GT, NVIDIA GeForce 7300 GT, PCIe, 256 MB
Memory Module: DIMM Riser A/DIMM 1, 1 GB, DDR2 FB-DIMM, 667 MHz
Memory Module: DIMM Riser A/DIMM 2, 1 GB, DDR2 FB-DIMM, 667 MHz
Memory Module: DIMM Riser B/DIMM 1, 1 GB, DDR2 FB-DIMM, 667 MHz
Memory Module: DIMM Riser B/DIMM 2, 1 GB, DDR2 FB-DIMM, 667 MHz
Memory Module: DIMM Riser A/DIMM 3, 1 GB, DDR2 FB-DIMM, 667 MHz
Memory Module: DIMM Riser A/DIMM 4, 1 GB, DDR2 FB-DIMM, 667 MHz
Memory Module: DIMM Riser B/DIMM 3, 1 GB, DDR2 FB-DIMM, 667 MHz
Memory Module: DIMM Riser B/DIMM 4, 1 GB, DDR2 FB-DIMM, 667 MHz
AirPort: spairport_wireless_card_type_airport_extreme (0x14E4, 0x87), Broadcom BCM43xx 1.0 (4.170.13.1)
Bluetooth: Version 1.9.5f4, 2 service, 1 devices, 1 incoming serial ports
Network Service: Built-in Ethernet 1, Ethernet, en0
PCI Card: NVIDIA GeForce 7300 GT, Display, Slot-4
PCI Card: NVIDIA GeForce 7300 GT, Display, Slot-1
Serial ATA Device: WDC WD5000AAKS-41TMA0, 465.76 GB
Parallel ATA Device: OPTIARC DVD RW AD-7170A
USB Device: Keyboard Hub, Apple, Inc., Up to 480 Mb/sec, 500 mA
USB Device: USB-PS/2 Optical Mouse, Logitech, Up to 1.5 Mb/sec, 100 mA
USB Device: psc 1310 series, hp, Up to 12 Mb/sec, 100 mA
USB Device: Apple Keyboard, Apple, Inc, Up to 1.5 Mb/sec, 100 mA
USB Device: Bluetooth USB Host Controller, Apple, Inc., Up to 12 Mb/sec, 500 mA
FireWire Device: built-in_hub, unknown_value, Unknown
FireWire Device: d2 Quadra (button), LaCie SA, Up to 800 Mb/sec
FireWire Device: (Rev 1.00), Tri-Select, Up to 400 Mb/sec
</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70476</commentid>
    <comment_count>5</comment_count>
    <who name="Dylan Schiemann">dylans</who>
    <bug_when>2008-02-12 21:04:22 -0800</bug_when>
    <thetext>(In reply to comment #3)
&gt; Can you please attach the crash logs from this crash?  See
&gt; &lt;http://webkit.org/quality/crashlogs.html&gt; for details.
&gt; 

Also crashes Leopard:

Process:         Safari [92873]
Path:            /Applications/WebKit.app/Contents/MacOS/WebKit
Identifier:      org.webkit.nightly.WebKit
Version:         r30153 (30153)
Code Type:       X86 (Native)
Parent Process:  launchd [78]

Date/Time:       2008-02-12 21:02:34.961 -0800
OS Version:      Mac OS X 10.5.1 (9B18)
Report Version:  6

Exception Type:  EXC_BAD_ACCESS (SIGSEGV)
Exception Codes: KERN_INVALID_ADDRESS at 0x00000000e8042488
Crashed Thread:  0

Thread 0 Crashed:
0   com.apple.WebCore             	0x00f0c48b WebCore::TextIterator::handleTextBox() + 587
1   com.apple.WebCore             	0x00f0d706 WebCore::TextIterator::advance() + 54
2   com.apple.WebCore             	0x00f0dbfb WebCore::plainTextToMallocAllocatedBuffer(WebCore::Range const*, unsigned int&amp;) + 187
3   com.apple.WebCore             	0x00f28042 -[WebCoreFrameBridge stringForRange:] + 50
4   com.apple.WebKit              	0x001be474 -[WebHTMLView(WebDocumentPrivateProtocols) string] + 84
5   com.apple.Safari              	0x00034ba1 0x1000 + 211873
6   com.apple.Safari              	0x00034724 0x1000 + 210724
7   com.apple.Safari              	0x00034416 0x1000 + 209942
8   com.apple.Safari              	0x00034302 0x1000 + 209666
9   com.apple.Foundation          	0x966c5663 __NSFireTimer + 147
10  com.apple.CoreFoundation      	0x95eaab7e CFRunLoopRunSpecific + 4494
11  com.apple.CoreFoundation      	0x95eaad38 CFRunLoopRunInMode + 88
12  com.apple.HIToolbox           	0x915d08a4 RunCurrentEventLoopInMode + 283
13  com.apple.HIToolbox           	0x915d06bd ReceiveNextEventCommon + 374
14  com.apple.HIToolbox           	0x915d0531 BlockUntilNextEventMatchingListInMode + 106
15  com.apple.AppKit              	0x9344fd5b _DPSNextEvent + 657
16  com.apple.AppKit              	0x9344f6a0 -[NSApplication nextEventMatchingMask:untilDate:inMode:dequeue:] + 128
17  com.apple.Safari              	0x00009d4e 0x1000 + 36174
18  com.apple.AppKit              	0x934486d1 -[NSApplication run] + 795
19  com.apple.AppKit              	0x934159ba NSApplicationMain + 574
20  com.apple.Safari              	0x00002876 0x1000 + 6262

Thread 1:
0   libSystem.B.dylib             	0x92144ace __semwait_signal + 10
1   libSystem.B.dylib             	0x9216eced pthread_cond_wait$UNIX2003 + 73
2   com.apple.WebCore             	0x00c3a85f WebCore::IconDatabase::syncThreadMainLoop() + 239
3   com.apple.WebCore             	0x00c3a975 WebCore::IconDatabase::iconDatabaseSyncThread() + 181
4   libSystem.B.dylib             	0x9216e075 _pthread_start + 321
5   libSystem.B.dylib             	0x9216df32 thread_start + 34

Thread 2:
0   libSystem.B.dylib             	0x9213d8e6 mach_msg_trap + 10
1   libSystem.B.dylib             	0x921450dc mach_msg + 72
2   com.apple.CoreFoundation      	0x95eaa0fe CFRunLoopRunSpecific + 1806
3   com.apple.CoreFoundation      	0x95eaad38 CFRunLoopRunInMode + 88
4   com.apple.CFNetwork           	0x933a17ba CFURLCacheWorkerThread(void*) + 396
5   libSystem.B.dylib             	0x9216e075 _pthread_start + 321
6   libSystem.B.dylib             	0x9216df32 thread_start + 34

Thread 3:
0   libSystem.B.dylib             	0x9213d8e6 mach_msg_trap + 10
1   libSystem.B.dylib             	0x921450dc mach_msg + 72
2   com.apple.CoreFoundation      	0x95eaa0fe CFRunLoopRunSpecific + 1806
3   com.apple.CoreFoundation      	0x95eaad38 CFRunLoopRunInMode + 88
4   com.apple.Foundation          	0x966f4560 +[NSURLConnection(NSURLConnectionReallyInternal) _resourceLoadLoop:] + 320
5   com.apple.Foundation          	0x9669104d -[NSThread main] + 45
6   com.apple.Foundation          	0x96690bf4 __NSThread__main__ + 308
7   libSystem.B.dylib             	0x9216e075 _pthread_start + 321
8   libSystem.B.dylib             	0x9216df32 thread_start + 34

Thread 4:
0   libSystem.B.dylib             	0x9218cf5a select$DARWIN_EXTSN + 10
1   libSystem.B.dylib             	0x9216e075 _pthread_start + 321
2   libSystem.B.dylib             	0x9216df32 thread_start + 34

Thread 0 crashed with X86 Thread State (32-bit):
  eax: 0x0015867b  ebx: 0x00f2801a  ecx: 0xe8042454  edx: 0xe8042454
  edi: 0xbfffea44  esi: 0xe8042454  ebp: 0xbfffe9b8  esp: 0xbfffe950
   ss: 0x0000001f  efl: 0x00010282  eip: 0x00f0c48b   cs: 0x00000017
   ds: 0x0000001f   es: 0x0000001f   fs: 0x00000000   gs: 0x00000037
  cr2: 0xe8042488

Binary Images:
    0x1000 -   0x12efef  com.apple.Safari 3.0.4 (5523.10.6) &lt;53d219fd878088543fd2e1af460bed18&gt; /Applications/Safari.app/Contents/MacOS/Safari
  0x176000 -   0x177ffc +WebKitNightlyEnabler.dylib ??? (???) /Applications/WebKit.app/Contents/Resources/WebKitNightlyEnabler.dylib
  0x17c000 -   0x23afff  com.apple.WebKit 525.8+ (525.8+) /Applications/WebKit.app/Contents/Frameworks/10.5/WebKit.framework/Versions/A/WebKit
  0x2d6000 -   0x2e4ff8  SyndicationUI ??? (???) &lt;8adc35e1eb5001dead3c18ee25f2e8db&gt; /System/Library/PrivateFrameworks/SyndicationUI.framework/Versions/A/SyndicationUI
  0x2f3000 -   0x3c1ff7  com.apple.JavaScriptCore 525.8+ (525.8+) /Applications/WebKit.app/Contents/Frameworks/10.5/JavaScriptCore.framework/Versions/A/JavaScriptCore
  0x47f000 -   0x481fff +net.culater.SIMBL 0.8.2 (8) /Library/InputManagers/SIMBL/SIMBL.bundle/Contents/MacOS/SIMBL
  0x61a000 -   0x61fff3  libCGXCoreImage.A.dylib ??? (???) &lt;1d164317677d5eb499d27388a0f0bb29&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libCGXCoreImage.A.dylib
  0xa3a000 -  0x1090fff  com.apple.WebCore 525.8+ (525.8+) /Applications/WebKit.app/Contents/Frameworks/10.5/WebCore.framework/Versions/A/WebCore
 0x1700000 -  0x17e6ff7  com.apple.RawCamera.bundle 2.0 (2.0) /System/Library/CoreServices/RawCamera.bundle/Contents/MacOS/RawCamera
0x16f4b000 - 0x16f4bffe  com.apple.JavaPluginCocoa 12.0.0 (12.0.0) &lt;02a9f23a8bfc902c32ac0adfb66d6816&gt; /Library/Internet Plug-Ins/JavaPluginCocoa.bundle/Contents/MacOS/JavaPluginCocoa
0x17593000 - 0x1759affd  com.apple.JavaVM 12.0.0 (12.0.0) &lt;44b9536fe4d7c7fcb3506adb695a180f&gt; /System/Library/Frameworks/JavaVM.framework/Versions/A/JavaVM
0x17cf4000 - 0x17cf5ff3  ATSHI.dylib ??? (???) /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ATS.framework/Versions/A/Resources/ATSHI.dylib
0x8fe00000 - 0x8fe2d883  dyld 95.3 (???) &lt;3896c718b33f3e065e199a659baf1a2b&gt; /usr/lib/dyld
0x90fbc000 - 0x91352ff7  com.apple.QuartzCore 1.5.1 (1.5.1) &lt;deb61cbeb3f734a1b2f4669f6268b9de&gt; /System/Library/Frameworks/QuartzCore.framework/Versions/A/QuartzCore
0x91353000 - 0x91371ff3  com.apple.DirectoryService.Framework 3.5 (3.5) &lt;55f196eadfd3ca73497d85aabd53c082&gt; /System/Library/Frameworks/DirectoryService.framework/Versions/A/DirectoryService
0x91372000 - 0x91404ff3  com.apple.ApplicationServices.ATS 3.0 (???) &lt;d994740916f7aa6495a3372def0e7b61&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ATS.framework/Versions/A/ATS
0x91405000 - 0x91411ff5  libGL.dylib ??? (???) /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGL.dylib
0x914f2000 - 0x9154fffb  libstdc++.6.dylib ??? (???) &lt;04b812dcec670daa8b7d2852ab14be60&gt; /usr/lib/libstdc++.6.dylib
0x91550000 - 0x915a0ff7  com.apple.HIServices 1.6.0 (???) &lt;d74aa73e4cfd30a08fb169198a8d2539&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/HIServices.framework/Versions/A/HIServices
0x915a1000 - 0x918a7fff  com.apple.HIToolbox 1.5.0 (???) &lt;baa49e74751bc3c4738509ba8cc512b1&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.framework/Versions/A/HIToolbox
0x91ab3000 - 0x91ab7fff  libGIF.dylib ??? (???) &lt;b8f61e346fa243a7138910bed3dcdb6b&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libGIF.dylib
0x91ae2000 - 0x91bc3ff7  libxml2.2.dylib ??? (???) &lt;450ec38b57fb46013847cce851001a2f&gt; /usr/lib/libxml2.2.dylib
0x91bc4000 - 0x91d8dfef  com.apple.security 5.0.1 (32736) &lt;8c9eda0fcc1d8a571543025ac900715f&gt; /System/Library/Frameworks/Security.framework/Versions/A/Security
0x91d8e000 - 0x91dbdfe3  com.apple.AE 402 (402) &lt;994ba8e884aefe7bf1fc5987df099e7b&gt; /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/AE.framework/Versions/A/AE
0x91e4f000 - 0x91e51fff  com.apple.CrashReporterSupport 10.5.0 (156) &lt;a9cf092be7a554b3cda00fe946d1c1a7&gt; /System/Library/PrivateFrameworks/CrashReporterSupport.framework/Versions/A/CrashReporterSupport
0x91e52000 - 0x91e53ffc  libffi.dylib ??? (???) &lt;a3b573eb950ca583290f7b2b4c486d09&gt; /usr/lib/libffi.dylib
0x91e54000 - 0x91e59fff  com.apple.CommonPanels 1.2.4 (85) &lt;ea0665f57cd267609466ed8b2b20e893&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/CommonPanels.framework/Versions/A/CommonPanels
0x91e5a000 - 0x91e60fff  com.apple.print.framework.Print 218 (220) &lt;c35172175abbe554ddadd9b6401351fa&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Print.framework/Versions/A/Print
0x91e7e000 - 0x91fa2fe3  com.apple.audio.toolbox.AudioToolbox 1.5 (1.5) /System/Library/Frameworks/AudioToolbox.framework/Versions/A/AudioToolbox
0x92013000 - 0x92021ffd  libz.1.dylib ??? (???) &lt;5ddd8539ae2ebfd8e7cc1c57525385c7&gt; /usr/lib/libz.1.dylib
0x92022000 - 0x9205bffe  com.apple.securityfoundation 3.0 (32768) &lt;1e9885d63ced51f81bc1f39af624637d&gt; /System/Library/Frameworks/SecurityFoundation.framework/Versions/A/SecurityFoundation
0x92124000 - 0x92131fe7  com.apple.opengl 1.5.5 (1.5.5) &lt;aa08b52d2a84b44dc6ee5d544a53fe8a&gt; /System/Library/Frameworks/OpenGL.framework/Versions/A/OpenGL
0x92132000 - 0x9213bfff  com.apple.speech.recognition.framework 3.7.24 (3.7.24) &lt;d3180f9edbd9a5e6f283d6156aa3c602&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/SpeechRecognition.framework/Versions/A/SpeechRecognition
0x9213c000 - 0x9213cff8  com.apple.Cocoa 6.5 (???) &lt;e064f94d969ce25cb7de3cfb980c3249&gt; /System/Library/Frameworks/Cocoa.framework/Versions/A/Cocoa
0x9213d000 - 0x92297fe3  libSystem.B.dylib ??? (???) &lt;08d9ec2f36455fc197b9b44adf62f304&gt; /usr/lib/libSystem.B.dylib
0x92298000 - 0x92299fef  libmathCommon.A.dylib ??? (???) /usr/lib/system/libmathCommon.A.dylib
0x9229a000 - 0x9230efef  libvMisc.dylib ??? (???) /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libvMisc.dylib
0x92783000 - 0x9278dfeb  com.apple.audio.SoundManager 3.9.2 (3.9.2) &lt;0f2ba6e891d3761212cf5a5e6134d683&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/CarbonSound.framework/Versions/A/CarbonSound
0x9278e000 - 0x9278effa  com.apple.CoreServices 32 (32) &lt;2fcc8f3bd5bbfc000b476cad8e6a3dd2&gt; /System/Library/Frameworks/CoreServices.framework/Versions/A/CoreServices
0x9278f000 - 0x927c5fef  libtidy.A.dylib ??? (???) &lt;e4d3e7399fb83d7f145f9b4ec8196242&gt; /usr/lib/libtidy.A.dylib
0x927c6000 - 0x927eeff7  com.apple.shortcut 1 (1.0) &lt;057783867138902b52bc0941fedb74d1&gt; /System/Library/PrivateFrameworks/Shortcut.framework/Versions/A/Shortcut
0x927ef000 - 0x927fffff  com.apple.speech.synthesis.framework 3.6.59 (3.6.59) &lt;4ffef145fad3d4d787e0c33eab26b336&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/SpeechSynthesis.framework/Versions/A/SpeechSynthesis
0x92800000 - 0x928dffff  libobjc.A.dylib ??? (???) &lt;5eda47fec2d0e7853b3506aa1fd2dafa&gt; /usr/lib/libobjc.A.dylib
0x9292d000 - 0x9296efe7  libRIP.A.dylib ??? (???) &lt;8aa8d17b338ebde48df7f01a8dc28eac&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libRIP.A.dylib
0x9296f000 - 0x9296fffd  com.apple.Accelerate 1.4 (Accelerate 1.4) /System/Library/Frameworks/Accelerate.framework/Versions/A/Accelerate
0x92970000 - 0x929ecfeb  com.apple.audio.CoreAudio 3.1.0 (3.1) &lt;483e0d3879d52ba9ac10b4bcfb0728d6&gt; /System/Library/Frameworks/CoreAudio.framework/Versions/A/CoreAudio
0x92a68000 - 0x92b69fff  com.apple.PubSub 1.0.1 (59) /System/Library/Frameworks/PubSub.framework/Versions/A/PubSub
0x92b6a000 - 0x92bf6ff7  com.apple.LaunchServices 286 (286) &lt;72b15e7a01e42d510f0339e90113d5d6&gt; /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/LaunchServices
0x92c2c000 - 0x92c5efff  com.apple.LDAPFramework 1.4.3 (106) &lt;94a26abfc0a5d88c752763b44a10ae51&gt; /System/Library/Frameworks/LDAP.framework/Versions/A/LDAP
0x92c5f000 - 0x92cbbff7  com.apple.htmlrendering 68 (1.1.3) &lt;fe87a9dede38db00e6c8949942c6bd4f&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HTMLRendering.framework/Versions/A/HTMLRendering
0x92cbc000 - 0x92cbcffd  com.apple.vecLib 3.4 (vecLib 3.4) /System/Library/Frameworks/vecLib.framework/Versions/A/vecLib
0x92cbd000 - 0x92cd3fff  com.apple.DictionaryServices 1.0.0 (1.0.0) &lt;ad0aa0252e3323d182e17f50defe56fc&gt; /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/DictionaryServices.framework/Versions/A/DictionaryServices
0x92cd4000 - 0x92cd9fff  com.apple.backup.framework 1.0 (1.0) /System/Library/PrivateFrameworks/Backup.framework/Versions/A/Backup
0x9323e000 - 0x9327bff7  libGLImage.dylib ??? (???) &lt;202d73e6a4688fc06ff11b71910c2ce7&gt; /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGLImage.dylib
0x9327c000 - 0x9327eff5  libRadiance.dylib ??? (???) &lt;b9e04afa91e4b597a00797d67a7268fb&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libRadiance.dylib
0x9327f000 - 0x932b9ff7  com.apple.coreui 0.1 (60) /System/Library/PrivateFrameworks/CoreUI.framework/Versions/A/CoreUI
0x932ba000 - 0x93385fff  com.apple.ColorSync 4.5.0 (4.5.0) /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ColorSync.framework/Versions/A/ColorSync
0x93386000 - 0x93395fff  libsasl2.2.dylib ??? (???) &lt;b9e1ca0b6612e280b6cbea6df0eec5f6&gt; /usr/lib/libsasl2.2.dylib
0x93396000 - 0x9340dfe3  com.apple.CFNetwork 220 (221) &lt;972a41911805859205b057a6f5b91e8d&gt; /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/CFNetwork.framework/Versions/A/CFNetwork
0x9340f000 - 0x93c09fef  com.apple.AppKit 6.5 (949) &lt;b7c57a0df7821668815329f17698d7ba&gt; /System/Library/Frameworks/AppKit.framework/Versions/C/AppKit
0x93c0a000 - 0x93c89ff5  com.apple.SearchKit 1.2.0 (1.2.0) &lt;277b460da86bc222785159fe77e2e2ed&gt; /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/SearchKit.framework/Versions/A/SearchKit
0x93c8a000 - 0x93c92fff  com.apple.DiskArbitration 2.2 (2.2) &lt;1551b2af557fdf6f368f93e093933852&gt; /System/Library/Frameworks/DiskArbitration.framework/Versions/A/DiskArbitration
0x93cd1000 - 0x93d36ffb  com.apple.ISSupport 1.6 (34) /System/Library/PrivateFrameworks/ISSupport.framework/Versions/A/ISSupport
0x93d3d000 - 0x93d3dffb  com.apple.installserver.framework 1.0 (8) /System/Library/PrivateFrameworks/InstallServer.framework/Versions/A/InstallServer
0x93d3e000 - 0x93d41fff  com.apple.help 1.1 (36) &lt;b507b08e484cb89033e9cf23062d77de&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Help.framework/Versions/A/Help
0x93d93000 - 0x941a3fef  libBLAS.dylib ??? (???) /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libBLAS.dylib
0x944c6000 - 0x94540ff8  com.apple.print.framework.PrintCore 5.5 (245) &lt;9441d178f4b430cf92b67bf346646693&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/PrintCore.framework/Versions/A/PrintCore
0x9463b000 - 0x9464affe  com.apple.DSObjCWrappers.Framework 1.2 (1.2) &lt;f5b58d1d3a855a63d493ccbec417a1e9&gt; /System/Library/PrivateFrameworks/DSObjCWrappers.framework/Versions/A/DSObjCWrappers
0x946ea000 - 0x9477dfff  com.apple.ink.framework 101.3 (86) &lt;bf3fa8927b4b8baae92381a976fd2079&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Ink.framework/Versions/A/Ink
0x9477e000 - 0x947abfeb  libvDSP.dylib ??? (???) &lt;a26683d121ee0f96df9a9d0bfca36049&gt; /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libvDSP.dylib
0x94819000 - 0x94ce5ffe  libGLProgrammability.dylib ??? (???) &lt;e8bc0af671427cf2b6279a035805a086&gt; /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGLProgrammability.dylib
0x94ce6000 - 0x94d98ffb  libcrypto.0.9.7.dylib ??? (???) &lt;330b0e48e67faffc8c22dfc069ca7a47&gt; /usr/lib/libcrypto.0.9.7.dylib
0x94d99000 - 0x94dd8fef  libTIFF.dylib ??? (???) &lt;76301b3506f310fb454b58897c8d0a9f&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libTIFF.dylib
0x94dd9000 - 0x94de9ffc  com.apple.LangAnalysis 1.6.4 (1.6.4) &lt;cbeb17ab39f28351fe2ab5b82bf465bc&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/LangAnalysis.framework/Versions/A/LangAnalysis
0x94dea000 - 0x94e2cfef  com.apple.NavigationServices 3.5.1 (161) &lt;cc6bd78eabf1e2e7166914e9f12f5850&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/NavigationServices.framework/Versions/A/NavigationServices
0x94e2d000 - 0x94e2dffd  com.apple.Accelerate.vecLib 3.4 (vecLib 3.4) /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/vecLib
0x94e2e000 - 0x94e87fff  libGLU.dylib ??? (???) /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGLU.dylib
0x94e96000 - 0x95014fff  com.apple.AddressBook.framework 4.1 (687) &lt;65b801e9f2cd16f4227d472aecb5deaf&gt; /System/Library/Frameworks/AddressBook.framework/Versions/A/AddressBook
0x95015000 - 0x95020fe7  libCSync.A.dylib ??? (???) &lt;482d16ba55f91a5dc05f78cc9db707a7&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libCSync.A.dylib
0x95021000 - 0x956b8fff  com.apple.CoreGraphics 1.351.0 (???) &lt;fc69a86d38421778ad5675b82c9c7da7&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/CoreGraphics
0x956b9000 - 0x956d8ffa  libJPEG.dylib ??? (???) &lt;0dd7e9d7fb22174b78205a944144f9c3&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libJPEG.dylib
0x956d9000 - 0x956e4ff9  com.apple.helpdata 1.0 (14) /System/Library/PrivateFrameworks/HelpData.framework/Versions/A/HelpData
0x956e5000 - 0x956fdfff  com.apple.openscripting 1.2.6 (???) &lt;b8e553df643f2aec68fa968b3b459b2b&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/OpenScripting.framework/Versions/A/OpenScripting
0x956ff000 - 0x95759ff7  com.apple.CoreText 2.0.0 (???) &lt;7fa39cd5bc847615ec02e7c7a37c0508&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreText.framework/Versions/A/CoreText
0x9575a000 - 0x957e1ff7  libsqlite3.0.dylib ??? (???) &lt;273efcb717e89c21207c851d7d33fda4&gt; /usr/lib/libsqlite3.0.dylib
0x957e2000 - 0x95abbfe7  com.apple.CoreServices.CarbonCore 783 (783) &lt;fe663a790344f1c5bac1645f68c7c661&gt; /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/CarbonCore.framework/Versions/A/CarbonCore
0x95b66000 - 0x95cabff7  com.apple.ImageIO.framework 2.0.0 (2.0.0) &lt;d6bf5dfae212dce267c2f6e50b2f23c6&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/ImageIO
0x95cac000 - 0x95cb3ff7  libCGATS.A.dylib ??? (???) &lt;dd3161e6653fa6400b9ef9c144309fa5&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libCGATS.A.dylib
0x95d70000 - 0x95d70fff  com.apple.Carbon 136 (136) &lt;9961570a497d79f13b8ea159826af42d&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Carbon
0x95d71000 - 0x95d78fe9  libgcc_s.1.dylib ??? (???) &lt;a9ab135a5f81f6e345527df87f51bfc9&gt; /usr/lib/libgcc_s.1.dylib
0x95d79000 - 0x95e20fff  com.apple.QD 3.11.50 (???) &lt;e2f71720ae1dad06a8883ac80775b21a&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/QD.framework/Versions/A/QD
0x95e21000 - 0x95e37fe7  com.apple.CoreVideo 1.5.0 (1.5.0) &lt;7e010557527a0e6d49147c297d16850a&gt; /System/Library/Frameworks/CoreVideo.framework/Versions/A/CoreVideo
0x95e38000 - 0x95f6afe7  com.apple.CoreFoundation 6.5 (476) &lt;8bfebc0dbad6fc33bea0fa00a1b9ec37&gt; /System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
0x95f6b000 - 0x95f95fef  libauto.dylib ??? (???) &lt;d468bc4a8a69343f1748c293db1b57fb&gt; /usr/lib/libauto.dylib
0x95f96000 - 0x96354fea  libLAPACK.dylib ??? (???) /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libLAPACK.dylib
0x96355000 - 0x96379feb  libssl.0.9.7.dylib ??? (???) &lt;acee7fc534674498dcac211318aa23e8&gt; /usr/lib/libssl.0.9.7.dylib
0x963ac000 - 0x96490ffb  com.apple.CoreData 100 (185) &lt;a4e63784275e25e62f57e75e0af0b94d&gt; /System/Library/Frameworks/CoreData.framework/Versions/A/CoreData
0x96491000 - 0x96491ffc  com.apple.audio.units.AudioUnit 1.5 (1.5) /System/Library/Frameworks/AudioUnit.framework/Versions/A/AudioUnit
0x96492000 - 0x96492ff8  com.apple.ApplicationServices 34 (34) &lt;8f910fa65f01d401ad8d04cc933cf887&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/ApplicationServices
0x96493000 - 0x96543fff  edu.mit.Kerberos 6.0.11 (6.0.11) &lt;33c25789baedcd70a7e24881775dd9ad&gt; /System/Library/Frameworks/Kerberos.framework/Versions/A/Kerberos
0x96544000 - 0x96558ff3  com.apple.ImageCapture 4.0 (5.0.0) /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/ImageCapture.framework/Versions/A/ImageCapture
0x96559000 - 0x965a3fe1  com.apple.securityinterface 3.0 (32532) &lt;f521dae416ce7a3bdd594b0d4e2fb517&gt; /System/Library/Frameworks/SecurityInterface.framework/Versions/A/SecurityInterface
0x965a4000 - 0x965dafff  com.apple.SystemConfiguration 1.9.0 (1.9.0) &lt;d78573acfd26322c0324e51b171f016c&gt; /System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfiguration
0x965db000 - 0x965f9fff  libresolv.9.dylib ??? (???) &lt;8538164a282c147c3543550ae49d4bd4&gt; /usr/lib/libresolv.9.dylib
0x965fa000 - 0x96621fff  libcups.2.dylib ??? (???) &lt;5521498e8902ddd0b15cfaa7db384e29&gt; /usr/lib/libcups.2.dylib
0x96622000 - 0x9663dffb  libPng.dylib ??? (???) &lt;85ca18172d7a4b5a5be3574e4e879880&gt; /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libPng.dylib
0x9663e000 - 0x96640fff  com.apple.securityhi 3.0 (30817) &lt;dbe328cd62d603a952a4226342711e8b&gt; /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/SecurityHI.framework/Versions/A/SecurityHI
0x9667f000 - 0x96686ffe  libbsm.dylib ??? (???) &lt;d25c63378a5029648ffd4b4669be31bf&gt; /usr/lib/libbsm.dylib
0x96687000 - 0x96900fe7  com.apple.Foundation 6.5.1 (677.1) &lt;85ac18c7cd454378db6122bea0c00965&gt; /System/Library/Frameworks/Foundation.framework/Versions/C/Foundation
0x9694f000 - 0x96a87ff7  libicucore.A.dylib ??? (???) &lt;afcea652ff2ec36885b2c81c57d06d4c&gt; /usr/lib/libicucore.A.dylib
0x96a88000 - 0x96b4fff2  com.apple.vImage 3.0 (3.0) /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vImage.framework/Versions/A/vImage
0x96b64000 - 0x96c1afe3  com.apple.CoreServices.OSServices 210.2 (210.2) &lt;4ed69f07fc0f211ab32d1ee96e281fc2&gt; /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/OSServices.framework/Versions/A/OSServices
0x96d72000 - 0x96e21fff  com.apple.DesktopServices 1.4.3 (1.4.3) &lt;66d5ed56111c43d234e235d365d02469&gt; /System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Versions/A/DesktopServicesPriv
0x96e28000 - 0x96e6dfef  com.apple.Metadata 10.5.0 (398) &lt;96d857e02d199e768919047b28ec95b3&gt; /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/Metadata.framework/Versions/A/Metadata
0x96e6e000 - 0x96e92fff  libxslt.1.dylib ??? (???) &lt;4933ddc7f6618743197aadc85b33b5ab&gt; /usr/lib/libxslt.1.dylib
0x96e93000 - 0x96f1dfff  com.apple.framework.IOKit 1.5.1 (???) &lt;5176a7383151a19c962334009fef2c6d&gt; /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
0xba900000 - 0xba916fff  libJapaneseConverter.dylib ??? (???) &lt;1e92e348e73fc6fce723936c11e4b25c&gt; /System/Library/CoreServices/Encodings/libJapaneseConverter.dylib
0xfffe8000 - 0xfffebfff  libobjc.A.dylib ??? (???) /usr/lib/libobjc.A.dylib
0xffff0000 - 0xffff1780  libSystem.B.dylib ??? (???) /usr/lib/libSystem.B.dylib

</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70485</commentid>
    <comment_count>6</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2008-02-12 23:55:53 -0800</bug_when>
    <thetext>The dojotoolkit.org server doesn&apos;t respond currently, waiting for it to come back.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70496</commentid>
    <comment_count>7</comment_count>
    <who name="Matthew Knapp">mdknapp</who>
    <bug_when>2008-02-13 02:06:00 -0800</bug_when>
    <thetext>I am able to access dojotoolkit.org now, so it appears to be back online.
(In reply to comment #6)
&gt; The dojotoolkit.org server doesn&apos;t respond currently, waiting for it to come
&gt; back.
&gt; </thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70497</commentid>
    <comment_count>8</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2008-02-13 02:30:58 -0800</bug_when>
    <thetext>I can reproduce this with a nightly, but not with a local debug build.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72549</commentid>
    <comment_count>9</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-03-03 00:02:39 -0800</bug_when>
    <thetext>&lt;rdar://problem/5776397&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72552</commentid>
    <comment_count>10</comment_count>
    <who name="David Smith">catfish.man</who>
    <bug_when>2008-03-03 02:02:17 -0800</bug_when>
    <thetext>http://paste.lisp.org/display/56721

Crashlogs from a debug build while we were testing this on irc tonight.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72559</commentid>
    <comment_count>11</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-03-03 03:45:04 -0800</bug_when>
    <thetext>I suspect the debug crash is a different issue, as the stack trace in a release build is very different.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72560</commentid>
    <comment_count>12</comment_count>
      <attachid>19491</attachid>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-03-03 04:02:04 -0800</bug_when>
    <thetext>Created attachment 19491
Reduction (will crash Release builds of TOT)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72561</commentid>
    <comment_count>13</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-03-03 04:06:54 -0800</bug_when>
    <thetext>I&apos;ve been debugging this for a few hours now and the situation seems quite bizarre.  It crashes consistently within RenderText::deleteTextBoxes while attempting to destroy a InlineTextBox.  This is due to the RenderText&apos;s m_firstTextBox having a bogus m_nextLine pointer.  This m_nextLine pointer is being set from CSSStyleSelector.cpp:1665.  Yes, that seems crazy, but at that point CSSStyleSelector&apos;s m_style/childStyle points to the same memory that is used by the InlineTextBox.  childStyle-&gt;setFirstChildState() ends up setting m_nextLine to 0x1000 rather than setting the bitfield member it intends to.  As to *why* a single memory location is being treated as a RenderStyle and InlineTextBox simultaneously... I have no idea at this point!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72562</commentid>
    <comment_count>14</comment_count>
      <attachid>19492</attachid>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-03-03 04:08:48 -0800</bug_when>
    <thetext>Created attachment 19492
Transcript of debugging session from point of crash

Points of interest here are the stack trace, and the value of this-&gt;m_firstTextBox-&gt;m_nextLine (0x1000).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72563</commentid>
    <comment_count>15</comment_count>
      <attachid>19493</attachid>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-03-03 04:11:12 -0800</bug_when>
    <thetext>Created attachment 19493
Transcript of debugging session from point of bogus write

Points of interest here are that childStyle looks like garbage when interpreted as a RenderStyle ($3), but looks sane and matches the InlineTextBox at point of crash when interpreted as an InlineTextBox ($4).  The transcript also shows the instruction that stores 0x1000 into memory, and that the address of the store corresponds to the offset of the m_nextLine member of an InlineTextBox instance.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72564</commentid>
    <comment_count>16</comment_count>
      <attachid>19494</attachid>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-03-03 04:30:24 -0800</bug_when>
    <thetext>Created attachment 19494
Crash under guard malloc

The reduction is small enough to run quickly under guard malloc, and it confirms the bogus write!  Under guard malloc, we conveniently crash at the point where the write occurs.  A little further poking around shows that the RenderStyle that previously resided at this memory location belonged to the &lt;input&gt; element, and is destroyed at the point of the following backtrace:

Breakpoint 2, WebCore::RenderStyle::~RenderStyle (this=0xd2641fbc) at WebCore/rendering/RenderStyle.cpp:1047
1047	}
#0  WebCore::RenderStyle::~RenderStyle (this=0xd2641fbc) at WebCore/rendering/RenderStyle.cpp:1047
#1  0x01f846f5 in WebCore::RenderStyle::~RenderStyle (this=0xd2641fbc) at WebCore/rendering/RenderStyle.cpp:1047
#2  0x01f84752 in WebCore::RenderStyle::arenaDelete (this=0xd2641fbc, arena=0xd1ea3e50) at WebCore/rendering/RenderStyle.cpp:924
#3  0x01b54139 in WebCore::RenderStyle::deref (this=0xd2641fbc, arena=0xd1ea3e50) at rendering/RenderStyle.h:1377
#4  0x01cb6955 in WebCore::Element::recalcStyle (this=0xd2569f80, change=WebCore::Node::Force) at WebCore/dom/Element.cpp:769
#5  0x01d40814 in WebCore::HTMLGenericFormElement::recalcStyle (this=0xd2569f80, change=WebCore::Node::Force) at WebCore/html/HTMLGenericFormElement.cpp:176
#6  0x01cb6a22 in WebCore::Element::recalcStyle (this=0xd252dfb0, change=WebCore::Node::Force) at WebCore/dom/Element.cpp:781
#7  0x01cb6a22 in WebCore::Element::recalcStyle (this=0xd21b7fb0, change=WebCore::Node::Force) at WebCore/dom/Element.cpp:781
#8  0x01c88a42 in WebCore::Document::recalcStyle (this=0xd1e72950, change=WebCore::Node::Force) at WebCore/dom/Document.cpp:1118
#9  0x01c8ab98 in WebCore::Document::updateStyleSelector (this=0xd1e72950) at WebCore/dom/Document.cpp:2068
#10 0x01cf1a37 in WebCore::Frame::reapplyStyles (this=0xc1d09ff0) at WebCore/page/Frame.cpp:755
#11 0x01d11786 in WebCore::FrameView::layout (this=0xc2ca3fd0, allowSubtree=true) at WebCore/page/FrameView.cpp:376
#12 0x01c85761 in WebCore::Document::implicitClose (this=0xd1e72950) at WebCore/dom/Document.cpp:1512
#13 0x01cf612e in WebCore::FrameLoader::checkCallImplicitClose (this=0xc1d11da0) at WebCore/loader/FrameLoader.cpp:1310
#14 0x01d019ae in WebCore::FrameLoader::checkCompleted (this=0xc1d11da0) at WebCore/loader/FrameLoader.cpp:1263


Perhaps someone that knows something (anything?) about how the CSS style system and rendering fit together would have more luck taking things from here?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72611</commentid>
    <comment_count>17</comment_count>
      <attachid>19503</attachid>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-03-03 14:18:17 -0800</bug_when>
    <thetext>Created attachment 19503
Patch

This fixes the reduced test case.  The original test case still crashes, though the crash is because of a different issue that I&apos;ll file as a new bug report.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72612</commentid>
    <comment_count>18</comment_count>
      <attachid>19503</attachid>
    <who name="">mitz</who>
    <bug_when>2008-03-03 14:23:24 -0800</bug_when>
    <thetext>Comment on attachment 19503
Patch

+            styleSelector-&gt;initForStyleResolve(static_cast&lt;Element*&gt;(n), 0);

You can use the &apos;element&apos; variable defined 2 lines above.

r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72615</commentid>
    <comment_count>19</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-03-03 14:44:55 -0800</bug_when>
    <thetext>Landed in r30722.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72620</commentid>
    <comment_count>20</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-03-03 15:06:11 -0800</bug_when>
    <thetext>Filed bug 17655 about the remaining crash.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>80684</commentid>
    <comment_count>21</comment_count>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2008-05-17 02:29:48 -0700</bug_when>
    <thetext>*** Bug 17408 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>19491</attachid>
            <date>2008-03-03 04:02:04 -0800</date>
            <delta_ts>2008-03-03 04:02:04 -0800</delta_ts>
            <desc>Reduction (will crash Release builds of TOT)</desc>
            <filename>bug-17313-reduction.html</filename>
            <type>text/html</type>
            <size>393</size>
            <attacher name="Mark Rowe (bdash)">mrowe</attacher>
            
              <data encoding="base64">PHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiPgogICAgd2luZG93Lm9ubG9hZCA9IGZ1bmN0
aW9uKCkgewogICAgICAgIGZ1bmN0aW9uIGRvUmVsb2FkKCkgewogICAgICAgICAgICB3aW5kb3cu
bG9jYXRpb24ucmVsb2FkKCk7CiAgICAgICAgfQoKICAgICAgICBmdW5jdGlvbiBkb1FTQSgpIHsK
ICAgICAgICAgICAgZG9jdW1lbnQucXVlcnlTZWxlY3RvckFsbCgnaDE6Zmlyc3QtY2hpbGQnKTsK
ICAgICAgICAgICAgd2luZG93LnNldFRpbWVvdXQoZG9SZWxvYWQsIDEwMCk7CiAgICAgICAgfQoK
ICAgICAgICB3aW5kb3cuc2V0VGltZW91dChkb1FTQSwgMTAwKTsKICAgIH0KPC9zY3JpcHQ+Cjxo
MT50ZXN0aW5nIGRvam8ucXVlcnkoKTwvaDE+CjxpbnB1dCB0eXBlPSJoaWRkZW4iPiAK
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>19492</attachid>
            <date>2008-03-03 04:08:48 -0800</date>
            <delta_ts>2008-03-03 04:08:48 -0800</delta_ts>
            <desc>Transcript of debugging session from point of crash</desc>
            <filename>point-of-crash.txt</filename>
            <type>text/plain</type>
            <size>5695</size>
            <attacher name="Mark Rowe (bdash)">mrowe</attacher>
            
              <data encoding="base64">KGdkYikgcgoKUHJvZ3JhbSByZWNlaXZlZCBzaWduYWwgRVhDX0JBRF9BQ0NFU1MsIENvdWxkIG5v
dCBhY2Nlc3MgbWVtb3J5LgpSZWFzb246IEtFUk5fSU5WQUxJRF9BRERSRVNTIGF0IGFkZHJlc3M6
IDB4ZmVlZGZhZDYKMHgwMTFhN2Y2ZSBpbiBXZWJDb3JlOjpSZW5kZXJUZXh0OjpkZWxldGVUZXh0
Qm94ZXMgKHRoaXM9MHgxZDNmOGE4KSBhdCBXZWJDb3JlL3JlbmRlcmluZy9SZW5kZXJUZXh0LmNw
cDoxOTMKMTkzCSAgICAgICAgICAgIGN1cnItPmRlc3Ryb3koYXJlbmEpOwooZ2RiKSBidAojMCAg
MHgwMTFhN2Y2ZSBpbiBXZWJDb3JlOjpSZW5kZXJUZXh0OjpkZWxldGVUZXh0Qm94ZXMgKHRoaXM9
MHgxZDNmOGE4KSBhdCBXZWJDb3JlL3JlbmRlcmluZy9SZW5kZXJUZXh0LmNwcDoxOTMKIzEgIDB4
MDExYTgwNTkgaW4gV2ViQ29yZTo6UmVuZGVyVGV4dDo6ZGVzdHJveSAodGhpcz0weDFkM2Y4YTgp
IGF0IFdlYkNvcmUvcmVuZGVyaW5nL1JlbmRlclRleHQuY3BwOjEzMQojMiAgMHgwMTExN2E3ZiBp
biBXZWJDb3JlOjpOb2RlOjpkZXRhY2ggKHRoaXM9MHgxN2I0M2NjMCkgYXQgV2ViQ29yZS9kb20v
Tm9kZS5jcHA6ODE3CiMzICAweDAwZTdkYTFiIGluIFdlYkNvcmU6OkNvbnRhaW5lck5vZGU6OmRl
dGFjaCAodGhpcz0weDE3OTM2ZjMwKSBhdCBXZWJDb3JlL2RvbS9Db250YWluZXJOb2RlLmNwcDo2
NjEKIzQgIDB4MDBlN2RhMWIgaW4gV2ViQ29yZTo6Q29udGFpbmVyTm9kZTo6ZGV0YWNoICh0aGlz
PTB4MTc5MzZmNzgpIGF0IFdlYkNvcmUvZG9tL0NvbnRhaW5lck5vZGUuY3BwOjY2MQojNSAgMHgw
MGU3ZGExYiBpbiBXZWJDb3JlOjpDb250YWluZXJOb2RlOjpkZXRhY2ggKHRoaXM9MHgxZDE1YWY4
KSBhdCBXZWJDb3JlL2RvbS9Db250YWluZXJOb2RlLmNwcDo2NjEKIzYgIDB4MDBlN2RhMWIgaW4g
V2ViQ29yZTo6Q29udGFpbmVyTm9kZTo6ZGV0YWNoICh0aGlzPTB4MWQzNDcwMCkgYXQgV2ViQ29y
ZS9kb20vQ29udGFpbmVyTm9kZS5jcHA6NjYxCiM3ICAweDAwZWZjNWQyIGluIFdlYkNvcmU6OkRv
Y3VtZW50OjpkZXRhY2ggKHRoaXM9MHgxZDM0NzAwKSBhdCBXZWJDb3JlL2RvbS9Eb2N1bWVudC5j
cHA6MTI1MQojOCAgMHgwMGY1MjAxOCBpbiBXZWJDb3JlOjpGcmFtZTo6c2V0VmlldyAodGhpcz0w
eDFkMDc1ZDAsIHZpZXc9MHgwKSBhdCBXZWJDb3JlL3BhZ2UvRnJhbWUuY3BwOjIxNwojOSAgMHgw
MTJjZjdkMyBpbiAtW1dlYkNvcmVGcmFtZUJyaWRnZSBjcmVhdGVGcmFtZVZpZXdXaXRoTlNWaWV3
Om1hcmdpbldpZHRoOm1hcmdpbkhlaWdodDpdIChzZWxmPTB4MWM3NjAzMCwgX2NtZD0weDMwNDhh
OCwgdmlldz0weDE3YTQzYTcwLCBtdz0tMSwgbWg9LTEpIGF0IFdlYkNvcmUvcGFnZS9tYWMvV2Vi
Q29yZUZyYW1lQnJpZGdlLm1tOjMxNAp3YXJuaW5nOiBpbnRlcm5hbCBlcnJvcjogbm8gQy9DKysg
ZnVuZGFtZW50YWwgdHlwZSAxCiMxMCAweDAwMjhhODQzIGluIFdlYkZyYW1lTG9hZGVyQ2xpZW50
Ojp0cmFuc2l0aW9uVG9Db21taXR0ZWRGb3JOZXdQYWdlICh0aGlzPTB4MWQxOTk2MCkgYXQgV2Vi
S2l0L21hYy9XZWJDb3JlU3VwcG9ydC9XZWJGcmFtZUxvYWRlckNsaWVudC5tbToxMDEyCiMxMSAw
eDAwZjZkMmNiIGluIFdlYkNvcmU6OkZyYW1lTG9hZGVyOjp0cmFuc2l0aW9uVG9Db21taXR0ZWQg
KHRoaXM9MHgxZDAwYTAwLCBjYWNoZWRQYWdlPUAweGJmZmZlMTZjKSBhdCBXZWJDb3JlL2xvYWRl
ci9GcmFtZUxvYWRlci5jcHA6MjYyNwojMTIgMHgwMGY2ZDk3YSBpbiBXZWJDb3JlOjpGcmFtZUxv
YWRlcjo6Y29tbWl0UHJvdmlzaW9uYWxMb2FkICh0aGlzPTB4MWQwMGEwMCwgcHJwQ2FjaGVkUGFn
ZT1AMHhmZWVkZmFjZSkgYXQgV2ViQ29yZS9sb2FkZXIvRnJhbWVMb2FkZXIuY3BwOjI1NDMKIzEz
IDB4MDBmMDkyMjUgaW4gV2ViQ29yZTo6RG9jdW1lbnRMb2FkZXI6OmNvbW1pdElmUmVhZHkgKHRo
aXM9MHgxZDJmMDAwKSBhdCBXZWJDb3JlL2xvYWRlci9Eb2N1bWVudExvYWRlci5jcHA6MzEyCiMx
NCAweDAwZjA5MjczIGluIFdlYkNvcmU6OkRvY3VtZW50TG9hZGVyOjpjb21taXRMb2FkICh0aGlz
PTB4MWQyZjAwMCwgZGF0YT0weDIxYzJjMjAgIjxodG1sPlxuXHQ8aGVhZD5cblx0ICAgIDxiYXNl
IGhyZWY9J2h0dHA6Ly9kb2pvdG9vbGtpdC5vcmcvfmFsZXgvYW5vbl92aWV3L2Rvam8vdGVzdHMv
X2Jhc2UvcXVlcnkuaHRtbCc+XG5cdFx0PHRpdGxlPnRlc3RpbmcgZG9qby5xdWVyeSgpPC90aXRs
ZT5cblx0XHQ8c3R5bGUgdHlwZT1cInRleHQvY3NzXCI+XG5cdFx0XHRAaW1wb3J0IFwiLi4vLi4v
cmVzb3VyY2VzL2Rvam8uY3MiLi4uLCBsZW5ndGg9NzA0MikgYXQgV2ViQ29yZS9sb2FkZXIvRG9j
dW1lbnRMb2FkZXIuY3BwOjM1MgojMTUgMHgwMTFjZjY5NSBpbiBXZWJDb3JlOjpSZXNvdXJjZUxv
YWRlcjo6ZGlkUmVjZWl2ZURhdGEgKHRoaXM9MHgxZDYzYzAwLCBkYXRhPTB4MjFjMmMyMCAiPGh0
bWw+XG5cdDxoZWFkPlxuXHQgICAgPGJhc2UgaHJlZj0naHR0cDovL2Rvam90b29sa2l0Lm9yZy9+
YWxleC9hbm9uX3ZpZXcvZG9qby90ZXN0cy9fYmFzZS9xdWVyeS5odG1sJz5cblx0XHQ8dGl0bGU+
dGVzdGluZyBkb2pvLnF1ZXJ5KCk8L3RpdGxlPlxuXHRcdDxzdHlsZSB0eXBlPVwidGV4dC9jc3Nc
Ij5cblx0XHRcdEBpbXBvcnQgXCIuLi8uLi9yZXNvdXJjZXMvZG9qby5jcyIuLi4sIGxlbmd0aD03
MDQyLCBsZW5ndGhSZWNlaXZlZD03MDQyLCBhbGxBdE9uY2U9ZmFsc2UpIGF0IFdlYkNvcmUvbG9h
ZGVyL1Jlc291cmNlTG9hZGVyLmNwcDoyMzYKIzE2IDB4MDExMDc1ZjcgaW4gV2ViQ29yZTo6TWFp
blJlc291cmNlTG9hZGVyOjpkaWRSZWNlaXZlRGF0YSAodGhpcz0weDFkNjNjMDAsIGRhdGE9MHgy
MWMyYzIwICI8aHRtbD5cblx0PGhlYWQ+XG5cdCAgICA8YmFzZSBocmVmPSdodHRwOi8vZG9qb3Rv
b2xraXQub3JnL35hbGV4L2Fub25fdmlldy9kb2pvL3Rlc3RzL19iYXNlL3F1ZXJ5Lmh0bWwnPlxu
XHRcdDx0aXRsZT50ZXN0aW5nIGRvam8ucXVlcnkoKTwvdGl0bGU+XG5cdFx0PHN0eWxlIHR5cGU9
XCJ0ZXh0L2Nzc1wiPlxuXHRcdFx0QGltcG9ydCBcIi4uLy4uL3Jlc291cmNlcy9kb2pvLmNzIi4u
LiwgbGVuZ3RoPTcwNDIsIGxlbmd0aFJlY2VpdmVkPTcwNDIsIGFsbEF0T25jZT1mYWxzZSkgYXQg
V2ViQ29yZS9sb2FkZXIvTWFpblJlc291cmNlTG9hZGVyLmNwcDoyOTkKIzE3IDB4MDExY2YxYjgg
aW4gV2ViQ29yZTo6UmVzb3VyY2VMb2FkZXI6OmRpZFJlY2VpdmVEYXRhICh0aGlzPTB4MTAwMCwg
ZGF0YT0weGZlZWRmYWNlIDxBZGRyZXNzIDB4ZmVlZGZhY2Ugb3V0IG9mIGJvdW5kcz4sIGxlbmd0
aD0tMTc5NTgxOTQsIGxlbmd0aFJlY2VpdmVkPS0xNzk1ODE5NCkgYXQgV2ViQ29yZS9sb2FkZXIv
UmVzb3VyY2VMb2FkZXIuY3BwOjM2NwojMTggMHg5NDFmZTNiNyBpbiAtW05TVVJMQ29ubmVjdGlv
bihOU1VSTENvbm5lY3Rpb25SZWFsbHlJbnRlcm5hbCkgc2VuZERpZFJlY2VpdmVEYXRhOm9yaWdp
bmFsTGVuZ3RoOl0gKCkKIzE5IDB4OTQxZmUzMWUgaW4gX05TVVJMQ29ubmVjdGlvbkRpZFJlY2Vp
dmVEYXRhICgpCiMyMCAweDk2ZjEzMGFmIGluIHNlbmREaWRSZWNlaXZlRGF0YUNhbGxiYWNrICgp
CiMyMSAweDk2ZjEwNzZkIGluIF9DRlVSTENvbm5lY3Rpb25TZW5kQ2FsbGJhY2tzICgpCiMyMiAw
eDk2ZjEwMGQ5IGluIG11eGVyU291cmNlUGVyZm9ybSAoKQojMjMgMHg5MjkwYTYyZSBpbiBDRlJ1
bkxvb3BSdW5TcGVjaWZpYyAoKQojMjQgMHg5MjkwYWQxOCBpbiBDRlJ1bkxvb3BSdW5Jbk1vZGUg
KCkKIzI1IDB4OTQ0M2I2YTAgaW4gUnVuQ3VycmVudEV2ZW50TG9vcEluTW9kZSAoKQojMjYgMHg5
NDQzYjRiOSBpbiBSZWNlaXZlTmV4dEV2ZW50Q29tbW9uICgpCiMyNyAweDk0NDNiMzJkIGluIEJs
b2NrVW50aWxOZXh0RXZlbnRNYXRjaGluZ0xpc3RJbk1vZGUgKCkKIzI4IDB4OTIwZGE3ZDkgaW4g
X0RQU05leHRFdmVudCAoKQojMjkgMHg5MjBkYTA4ZSBpbiAtW05TQXBwbGljYXRpb24gbmV4dEV2
ZW50TWF0Y2hpbmdNYXNrOnVudGlsRGF0ZTppbk1vZGU6ZGVxdWV1ZTpdICgpCiMzMCAweDAwMDFk
NDJlIGluIC1bQnJvd3NlckFwcGxpY2F0aW9uIG5leHRFdmVudE1hdGNoaW5nTWFzazp1bnRpbERh
dGU6aW5Nb2RlOmRlcXVldWU6XSAoc2VsZj0weDFjMTliYTAsIF9jbWQ9MHg5NDk3OWJlMCwgbWFz
az00Mjc3MDA5MTAyLCBleHBpcmF0aW9uPTB4ZmVlZGZhY2UsIG1vZGU9MHhhMDJkYmIzMCwgZGVx
dWV1ZT0xICdcMDAxJykgYXQgL1ZvbHVtZXMvRGF0YS9Ib21lL0RvY3VtZW50cy9Xb3JrL1dlYktp
dC1naXQvSW50ZXJuYWwvU2FmYXJpL21hYy9Ccm93c2VyQXBwbGljYXRpb24ubToxNTQKIzMxIDB4
OTIwZDMwYzUgaW4gLVtOU0FwcGxpY2F0aW9uIHJ1bl0gKCkKIzMyIDB4OTIwYTAzMGEgaW4gTlNB
cHBsaWNhdGlvbk1haW4gKCkKIzMzIDB4MDAwMDJhMTYgaW4gc3RhcnQgKCkKKGdkYikgcHJpbnQg
KnRoaXMtPm1fZmlyc3RUZXh0Qm94ICAKJDEgPSB7CiAgPFdlYkNvcmU6OklubGluZVJ1bkJveD4g
PSB7CiAgICA8V2ViQ29yZTo6SW5saW5lQm94PiA9IHsKICAgICAgX3ZwdHIkSW5saW5lQm94ID0g
MHgwLCAKICAgICAgbV9vYmplY3QgPSAweDFkM2Y4YTgsIAogICAgICBtX3ggPSAwLCAKICAgICAg
bV95ID0gLTEsIAogICAgICBtX3dpZHRoID0gMTcyLCAKICAgICAgbV9oZWlnaHQgPSAyMiwgCiAg
ICAgIG1fYmFzZWxpbmUgPSAxOCwgCiAgICAgIG1fbmV4dCA9IDB4MCwgCiAgICAgIG1fcHJldiA9
IDB4MCwgCiAgICAgIG1fcGFyZW50ID0gMHgxZDNlYTU0LCAKICAgICAgbV9maXJzdExpbmUgPSB0
cnVlLCAKICAgICAgbV9jb25zdHJ1Y3RlZCA9IHRydWUsIAogICAgICBtX2RpcnR5ID0gZmFsc2Us
IAogICAgICBtX2V4dHJhY3RlZCA9IGZhbHNlLCAKICAgICAgbV9pbmNsdWRlTGVmdEVkZ2UgPSBm
YWxzZSwgCiAgICAgIG1faW5jbHVkZVJpZ2h0RWRnZSA9IGZhbHNlLCAKICAgICAgbV9oYXNUZXh0
Q2hpbGRyZW4gPSB0cnVlLCAKICAgICAgbV9lbmRzV2l0aEJyZWFrID0gZmFsc2UsIAogICAgICBt
X2hhc1NlbGVjdGVkQ2hpbGRyZW4gPSBmYWxzZSwgCiAgICAgIG1faGFzRWxsaXBzaXNCb3ggPSBm
YWxzZSwgCiAgICAgIG1fcmV2ZXJzZWQgPSBmYWxzZSwgCiAgICAgIG1fZGlyT3ZlcnJpZGUgPSBm
YWxzZSwgCiAgICAgIG1fdHJlYXRBc1RleHQgPSB0cnVlLCAKICAgICAgbV9kZXRlcm1pbmVkSWZO
ZXh0T25MaW5lRXhpc3RzID0gZmFsc2UsIAogICAgICBtX2RldGVybWluZWRJZlByZXZPbkxpbmVF
eGlzdHMgPSBmYWxzZSwgCiAgICAgIG1fbmV4dE9uTGluZUV4aXN0cyA9IGZhbHNlLCAKICAgICAg
bV9wcmV2T25MaW5lRXhpc3RzID0gZmFsc2UsIAogICAgICBtX3RvQWRkID0gMAogICAgfSwgCiAg
ICBtZW1iZXJzIG9mIFdlYkNvcmU6OklubGluZVJ1bkJveDogCiAgICBtX3ByZXZMaW5lID0gMHgw
LCAKICAgIG1fbmV4dExpbmUgPSAweDEwMDAKICB9LCAKICBtZW1iZXJzIG9mIFdlYkNvcmU6Oklu
bGluZVRleHRCb3g6IAogIG1fc3RhcnQgPSAwLCAKICBtX2xlbiA9IDIwLCAKICBtX3RydW5jYXRp
b24gPSA2NTUzNQp9CihnZGIpIHByaW50IHRoaXMtPm1fZmlyc3RUZXh0Qm94LT5tX25leHRMaW5l
IAokMiA9IChXZWJDb3JlOjpJbmxpbmVSdW5Cb3ggKikgMHgxMDAwCihnZGIpIHByaW50IGN1cnIK
JDMgPSAoY2xhc3MgV2ViQ29yZTo6SW5saW5lVGV4dEJveCAqKSAweDEwMDAKKGdkYikgCg==
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>19493</attachid>
            <date>2008-03-03 04:11:12 -0800</date>
            <delta_ts>2008-03-03 04:11:12 -0800</delta_ts>
            <desc>Transcript of debugging session from point of bogus write</desc>
            <filename>point-of-bogus-write.txt</filename>
            <type>text/plain</type>
            <size>4472</size>
            <attacher name="Mark Rowe (bdash)">mrowe</attacher>
            
              <data encoding="base64">KGdkYikgcgoKQnJlYWtwb2ludCAxLCBXZWJDb3JlOjpDU1NTdHlsZVNlbGVjdG9yOjpjaGVja09u
ZVNlbGVjdG9yICh0aGlzPTB4MWQ0MWRjMCwgc2VsPTB4MWRlYjYwMCwgZT0weDE3OTM2ZjMwLCBp
c0FuY2VzdG9yPXRydWUsIGlzU3ViU2VsZWN0b3I9ZmFsc2UpIGF0IFdlYkNvcmUvY3NzL0NTU1N0
eWxlU2VsZWN0b3IuY3BwOjE2NjQKMTY2NAkgICAgICAgICAgICAgICAgICAgICAgICBpZiAocmVz
dWx0ICYmIGNoaWxkU3R5bGUpCihnZGIpIGxpc3QgMTY1OSwgMTY2MgoxNjU5CSAgICAgICAgICAg
ICAgICAgICAgaWYgKCFtX2NvbGxlY3RSdWxlc09ubHkpIHsKMTY2MAkgICAgICAgICAgICAgICAg
ICAgICAgICBSZW5kZXJTdHlsZSogY2hpbGRTdHlsZSA9IChtX2VsZW1lbnQgPT0gZSkgPyBtX3N0
eWxlIDogZS0+cmVuZGVyU3R5bGUoKTsKMTY2MQkgICAgICAgICAgICAgICAgICAgICAgICBSZW5k
ZXJTdHlsZSogcGFyZW50U3R5bGUgPSAobV9lbGVtZW50ID09IGUpID8gbV9wYXJlbnRTdHlsZSA6
IGUtPnBhcmVudE5vZGUoKS0+cmVuZGVyU3R5bGUoKTsKMTY2MgkgICAgICAgICAgICAgICAgICAg
ICAgICBpZiAocGFyZW50U3R5bGUpCihnZGIpIHByaW50IGNoaWxkU3R5bGUKJDEgPSAoV2ViQ29y
ZTo6UmVuZGVyU3R5bGUgKikgMHgxZDNlODg0CihnZGIpIHByaW50IHRoaXMtPm1fc3R5bGUKJDIg
PSAoV2ViQ29yZTo6UmVuZGVyU3R5bGUgKikgMHgxZDNlODg0CihnZGIpIHByaW50ICpjaGlsZFN0
eWxlCiQzID0gewogIHN0YXRpYyBGSVJTVF9JTlRFUk5BTF9QU0VVRE9JRCA9IDcsIAogIGluaGVy
aXRlZF9mbGFncyA9IHsKICAgIF9lbXB0eV9jZWxscyA9IDAsIAogICAgX2NhcHRpb25fc2lkZSA9
IDAsIAogICAgX2xpc3Rfc3R5bGVfdHlwZSA9IDksIAogICAgX2xpc3Rfc3R5bGVfcG9zaXRpb24g
PSAwLCAKICAgIF92aXNpYmlsaXR5ID0gMCwgCiAgICBfdGV4dF9hbGlnbiA9IDMsIAogICAgX3Rl
eHRfdHJhbnNmb3JtID0gMSwgCiAgICBfdGV4dF9kZWNvcmF0aW9ucyA9IDMsIAogICAgX2N1cnNv
cl9zdHlsZSA9IDEwLCAKICAgIF9kaXJlY3Rpb24gPSAwLCAKICAgIF9ib3JkZXJfY29sbGFwc2Ug
PSBmYWxzZSwgCiAgICBfd2hpdGVfc3BhY2UgPSAwLCAKICAgIF9ib3hfZGlyZWN0aW9uID0gMCwg
CiAgICBfdmlzdWFsbHlPcmRlcmVkID0gZmFsc2UsIAogICAgX2h0bWxIYWNrcyA9IGZhbHNlLCAK
ICAgIF9mb3JjZV9iYWNrZ3JvdW5kc190b193aGl0ZSA9IHRydWUKICB9LCAKICBub25pbmhlcml0
ZWRfZmxhZ3MgPSB7CiAgICBfZWZmZWN0aXZlRGlzcGxheSA9IDAsIAogICAgX29yaWdpbmFsRGlz
cGxheSA9IDAsIAogICAgX2JnX3JlcGVhdCA9IDAsIAogICAgX292ZXJmbG93WCA9IDAsIAogICAg
X292ZXJmbG93WSA9IDAsIAogICAgX3ZlcnRpY2FsX2FsaWduID0gMCwgCiAgICBfY2xlYXIgPSAw
LCAKICAgIF9wb3NpdGlvbiA9IDAsIAogICAgX2Zsb2F0aW5nID0gMCwgCiAgICBfdGFibGVfbGF5
b3V0ID0gMCwgCiAgICBfcGFnZV9icmVha19iZWZvcmUgPSAzLCAKICAgIF9wYWdlX2JyZWFrX2Fm
dGVyID0gMywgCiAgICBfc3R5bGVUeXBlID0gMzEsIAogICAgX2FmZmVjdGVkQnlIb3ZlciA9IHRy
dWUsIAogICAgX2FmZmVjdGVkQnlBY3RpdmUgPSB0cnVlLCAKICAgIF9hZmZlY3RlZEJ5RHJhZyA9
IHRydWUsIAogICAgX3BzZXVkb0JpdHMgPSA2MywgCiAgICBfdW5pY29kZUJpZGkgPSAzCiAgfSwg
CiAgYm94ID0gewogICAgbV9kYXRhID0gewogICAgICBtX3B0ciA9IDB4YWMKICAgIH0KICB9LCAK
ICB2aXN1YWwgPSB7CiAgICBtX2RhdGEgPSB7CiAgICAgIG1fcHRyID0gMHgxNgogICAgfQogIH0s
IAogIGJhY2tncm91bmQgPSB7CiAgICBtX2RhdGEgPSB7CiAgICAgIG1fcHRyID0gMHgxMgogICAg
fQogIH0sIAogIHN1cnJvdW5kID0gewogICAgbV9kYXRhID0gewogICAgICBtX3B0ciA9IDB4MAog
ICAgfQogIH0sIAogIHJhcmVOb25Jbmhlcml0ZWREYXRhID0gewogICAgbV9kYXRhID0gewogICAg
ICBtX3B0ciA9IDB4MAogICAgfQogIH0sIAogIHJhcmVJbmhlcml0ZWREYXRhID0gewogICAgbV9k
YXRhID0gewogICAgICBtX3B0ciA9IDB4MWQzZWE1NAogICAgfQogIH0sIAogIGluaGVyaXRlZCA9
IHsKICAgIG1fZGF0YSA9IHsKICAgICAgbV9wdHIgPSAweDEwNDMKICAgIH0KICB9LCAKICBwc2V1
ZG9TdHlsZSA9IDB4MCwgCiAgbV9wc2V1ZG9TdGF0ZSA9IDAsIAogIG1fYWZmZWN0ZWRCeUF0dHJp
YnV0ZVNlbGVjdG9ycyA9IGZhbHNlLCAKICBtX3VuaXF1ZSA9IGZhbHNlLCAKICBtX2FmZmVjdGVk
QnlFbXB0eSA9IGZhbHNlLCAKICBtX2VtcHR5U3RhdGUgPSBmYWxzZSwgCiAgbV9jaGlsZHJlbkFm
ZmVjdGVkQnlGaXJzdENoaWxkUnVsZXMgPSBmYWxzZSwgCiAgbV9jaGlsZHJlbkFmZmVjdGVkQnlM
YXN0Q2hpbGRSdWxlcyA9IGZhbHNlLCAKICBtX2NoaWxkcmVuQWZmZWN0ZWRCeURpcmVjdEFkamFj
ZW50UnVsZXMgPSBmYWxzZSwgCiAgbV9jaGlsZHJlbkFmZmVjdGVkQnlGb3J3YXJkUG9zaXRpb25h
bFJ1bGVzID0gZmFsc2UsIAogIG1fY2hpbGRyZW5BZmZlY3RlZEJ5QmFja3dhcmRQb3NpdGlvbmFs
UnVsZXMgPSBmYWxzZSwgCiAgbV9maXJzdENoaWxkU3RhdGUgPSBmYWxzZSwgCiAgbV9sYXN0Q2hp
bGRTdGF0ZSA9IGZhbHNlLCAKICBtX2NoaWxkSW5kZXggPSAwLCAKICBtX3JlZiA9IDAsIAogIG1f
c3ZnU3R5bGUgPSB7CiAgICBtX2RhdGEgPSB7CiAgICAgIG1fcHRyID0gMHhmZmZmMDAxNAogICAg
fQogIH0KfQooZ2RiKSBwcmludCAqKElubGluZVRleHRCb3gqKWNoaWxkU3R5bGUKJDQgPSB7CiAg
PFdlYkNvcmU6OklubGluZVJ1bkJveD4gPSB7CiAgICA8V2ViQ29yZTo6SW5saW5lQm94PiA9IHsK
ICAgICAgX3ZwdHIkSW5saW5lQm94ID0gMHgxNDY5ODQ4LCAKICAgICAgbV9vYmplY3QgPSAweDFk
M2Y4YTgsIAogICAgICBtX3ggPSAwLCAKICAgICAgbV95ID0gLTEsIAogICAgICBtX3dpZHRoID0g
MTcyLCAKICAgICAgbV9oZWlnaHQgPSAyMiwgCiAgICAgIG1fYmFzZWxpbmUgPSAxOCwgCiAgICAg
IG1fbmV4dCA9IDB4MCwgCiAgICAgIG1fcHJldiA9IDB4MCwgCiAgICAgIG1fcGFyZW50ID0gMHgx
ZDNlYTU0LCAKICAgICAgbV9maXJzdExpbmUgPSB0cnVlLCAKICAgICAgbV9jb25zdHJ1Y3RlZCA9
IHRydWUsIAogICAgICBtX2RpcnR5ID0gZmFsc2UsIAogICAgICBtX2V4dHJhY3RlZCA9IGZhbHNl
LCAKICAgICAgbV9pbmNsdWRlTGVmdEVkZ2UgPSBmYWxzZSwgCiAgICAgIG1faW5jbHVkZVJpZ2h0
RWRnZSA9IGZhbHNlLCAKICAgICAgbV9oYXNUZXh0Q2hpbGRyZW4gPSB0cnVlLCAKICAgICAgbV9l
bmRzV2l0aEJyZWFrID0gZmFsc2UsIAogICAgICBtX2hhc1NlbGVjdGVkQ2hpbGRyZW4gPSBmYWxz
ZSwgCiAgICAgIG1faGFzRWxsaXBzaXNCb3ggPSBmYWxzZSwgCiAgICAgIG1fcmV2ZXJzZWQgPSBm
YWxzZSwgCiAgICAgIG1fZGlyT3ZlcnJpZGUgPSBmYWxzZSwgCiAgICAgIG1fdHJlYXRBc1RleHQg
PSB0cnVlLCAKICAgICAgbV9kZXRlcm1pbmVkSWZOZXh0T25MaW5lRXhpc3RzID0gZmFsc2UsIAog
ICAgICBtX2RldGVybWluZWRJZlByZXZPbkxpbmVFeGlzdHMgPSBmYWxzZSwgCiAgICAgIG1fbmV4
dE9uTGluZUV4aXN0cyA9IGZhbHNlLCAKICAgICAgbV9wcmV2T25MaW5lRXhpc3RzID0gZmFsc2Us
IAogICAgICBtX3RvQWRkID0gMAogICAgfSwgCiAgICBtZW1iZXJzIG9mIFdlYkNvcmU6OklubGlu
ZVJ1bkJveDogCiAgICBtX3ByZXZMaW5lID0gMHgwLCAKICAgIG1fbmV4dExpbmUgPSAweDAKICB9
LCAKICBtZW1iZXJzIG9mIFdlYkNvcmU6OklubGluZVRleHRCb3g6IAogIG1fc3RhcnQgPSAwLCAK
ICBtX2xlbiA9IDIwLCAKICBtX3RydW5jYXRpb24gPSA2NTUzNQp9CihnZGIpIGluZm8gbGluZSAx
NjY0CkxpbmUgMTY2NCBvZiAiV2ViQ29yZS9jc3MvQ1NTU3R5bGVTZWxlY3Rvci5jcHAiIHN0YXJ0
cyBhdCBhZGRyZXNzIDB4ZTNjMjcwIDxfWk43V2ViQ29yZTE2Q1NTU3R5bGVTZWxlY3RvcjE2Y2hl
Y2tPbmVTZWxlY3RvckVQTlNfMTFDU1NTZWxlY3RvckVQTlNfN0VsZW1lbnRFYmIrMzY4MD4gYW5k
IGVuZHMgYXQgMHhlM2MyN2EgPF9aTjdXZWJDb3JlMTZDU1NTdHlsZVNlbGVjdG9yMTZjaGVja09u
ZVNlbGVjdG9yRVBOU18xMUNTU1NlbGVjdG9yRVBOU183RWxlbWVudEViYiszNjkwPi4KKGdkYikg
ZGlzYXMgMHhlM2MyN2EgMHhlM2MyN2IKRHVtcCBvZiBhc3NlbWJsZXIgY29kZSBmcm9tIDB4ZTNj
MjdhIHRvIDB4ZTNjMjdiOgoweDAwZTNjMjdhIDxfWk43V2ViQ29yZTE2Q1NTU3R5bGVTZWxlY3Rv
cjE2Y2hlY2tPbmVTZWxlY3RvckVQTlNfMTFDU1NTZWxlY3RvckVQTlNfN0VsZW1lbnRFYmIrMzY5
MD46CW9ybCAgICAkMHgxMDAwLDB4MzAoJWVzaSkKRW5kIG9mIGFzc2VtYmxlciBkdW1wLgooZ2Ri
KSBwcmludCAkZXNpKzB4MzAgPT0gJigoSW5saW5lVGV4dEJveCopdGhpcy0+bV9zdHlsZSktPm1f
bmV4dExpbmUKJDUgPSB0cnVlCihnZGIpIAo=
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>19494</attachid>
            <date>2008-03-03 04:30:24 -0800</date>
            <delta_ts>2008-03-03 04:30:24 -0800</delta_ts>
            <desc>Crash under guard malloc</desc>
            <filename>crash-under-guard-malloc.txt</filename>
            <type>text/plain</type>
            <size>4264</size>
            <attacher name="Mark Rowe (bdash)">mrowe</attacher>
            
              <data encoding="base64">UHJvZ3JhbSByZWNlaXZlZCBzaWduYWwgRVhDX0JBRF9BQ0NFU1MsIENvdWxkIG5vdCBhY2Nlc3Mg
bWVtb3J5LgpSZWFzb246IEtFUk5fSU5WQUxJRF9BRERSRVNTIGF0IGFkZHJlc3M6IDB4ZDI2M2Rm
ZWMKMHgwMWJjOTY5ZCBpbiBXZWJDb3JlOjpSZW5kZXJTdHlsZTo6c2V0Rmlyc3RDaGlsZFN0YXRl
ICh0aGlzPTB4ZDI2M2RmYmMpIGF0IHJlbmRlcmluZy9SZW5kZXJTdHlsZS5oOjIxODEKMjE4MQkg
ICAgdm9pZCBzZXRGaXJzdENoaWxkU3RhdGUoKSB7IG1fZmlyc3RDaGlsZFN0YXRlID0gdHJ1ZTsg
fQooZ2RiKSBidAojMCAgMHgwMWJjOTY5ZCBpbiBXZWJDb3JlOjpSZW5kZXJTdHlsZTo6c2V0Rmly
c3RDaGlsZFN0YXRlICh0aGlzPTB4ZDI2M2RmYmMpIGF0IHJlbmRlcmluZy9SZW5kZXJTdHlsZS5o
OjIxODEKIzEgIDB4MDFiYjNiYWUgaW4gV2ViQ29yZTo6Q1NTU3R5bGVTZWxlY3Rvcjo6Y2hlY2tP
bmVTZWxlY3RvciAodGhpcz0weGQyNWUzZWMwLCBzZWw9MHhkODlhOWZlMCwgZT0weGQyNTI3ZmIw
LCBpc0FuY2VzdG9yPXRydWUsIGlzU3ViU2VsZWN0b3I9ZmFsc2UpIGF0IFdlYkNvcmUvY3NzL0NT
U1N0eWxlU2VsZWN0b3IuY3BwOjE2NjUKIzIgIDB4MDFiYjVhYzMgaW4gV2ViQ29yZTo6Q1NTU3R5
bGVTZWxlY3Rvcjo6Y2hlY2tTZWxlY3RvciAodGhpcz0weGQyNWUzZWMwLCBzZWw9MHhkODlhOWZl
MCwgZT0weGQyNTI3ZmIwLCBpc0FuY2VzdG9yPXRydWUsIGlzU3ViU2VsZWN0b3I9ZmFsc2UpIGF0
IFdlYkNvcmUvY3NzL0NTU1N0eWxlU2VsZWN0b3IuY3BwOjEzOTEKIzMgIDB4MDFiYjVmYjYgaW4g
V2ViQ29yZTo6Q1NTU3R5bGVTZWxlY3Rvcjo6Y2hlY2tTZWxlY3RvciAodGhpcz0weGQyNWUzZWMw
LCBzZWw9MHhkODlhOWZlMCkgYXQgV2ViQ29yZS9jc3MvQ1NTU3R5bGVTZWxlY3Rvci5jcHA6MTM2
NgojNCAgMHgwMjE1MDY2NSBpbiBXZWJDb3JlOjpTZWxlY3Rvck5vZGVMaXN0OjpTZWxlY3Rvck5v
ZGVMaXN0ICh0aGlzPTB4ZDg5YjdmZTAsIHJvb3ROb2RlPUAweGJmZmZlMTc0LCBxdWVyeVNlbGVj
dG9yPTB4ZDg5YTlmZTApIGF0IFdlYkNvcmUvZG9tL1NlbGVjdG9yTm9kZUxpc3QuY3BwOjQ4CiM1
ICAweDAyMTUwNmUxIGluIFdlYkNvcmU6OlNlbGVjdG9yTm9kZUxpc3Q6OlNlbGVjdG9yTm9kZUxp
c3QgKHRoaXM9MHhkODliN2ZlMCwgcm9vdE5vZGU9QDB4YmZmZmUxNzQsIHF1ZXJ5U2VsZWN0b3I9
MHhkODlhOWZlMCkgYXQgV2ViQ29yZS9kb20vU2VsZWN0b3JOb2RlTGlzdC5jcHA6NTUKIzYgIDB4
MDFlZTI5MWQgaW4gV2ViQ29yZTo6Tm9kZTo6cXVlcnlTZWxlY3RvckFsbCAodGhpcz0weGQxZTZl
OTUwLCBzZWxlY3RvcnM9QDB4YmZmZmUxYzgsIGVjPUAweGJmZmZlMWNjKSBhdCBXZWJDb3JlL2Rv
bS9Ob2RlLmNwcDoxMjQ5CiM3ICAweDAxZGY2OGQ1IGluIFdlYkNvcmU6OmpzRG9jdW1lbnRQcm90
b3R5cGVGdW5jdGlvblF1ZXJ5U2VsZWN0b3JBbGwgKGV4ZWM9MHhiZmZmZTQxMCwgdGhpc09iaj0w
eDE4YzUwY2UwLCBhcmdzPUAweGJmZmZlMjgwKSBhdCBXZWJLaXRCdWlsZC9EZWJ1Zy9EZXJpdmVk
U291cmNlcy9XZWJDb3JlL0pTRG9jdW1lbnQuY3BwOjEwOTQKIzggIDB4MDA1YTJhZGEgaW4gS0pT
OjpQcm90b3R5cGVGdW5jdGlvbjo6Y2FsbEFzRnVuY3Rpb24gKHRoaXM9MHgxOGM1MGQwMCwgZXhl
Yz0weGJmZmZlNDEwLCB0aGlzT2JqPTB4MThjNTBjZTAsIGFyZ3M9QDB4YmZmZmUyODApIGF0IGZ1
bmN0aW9uLmNwcDo4OTEKIzkgIDB4MDA1YzY5MzIgaW4gS0pTOjpKU09iamVjdDo6Y2FsbCAodGhp
cz0weDE4YzUwZDAwLCBleGVjPTB4YmZmZmU0MTAsIHRoaXNPYmo9MHgxOGM1MGNlMCwgYXJncz1A
MHhiZmZmZTI4MCkgYXQgb2JqZWN0LmNwcDo5NgojMTAgMHgwMDYxYThkOCBpbiBLSlM6OkZ1bmN0
aW9uQ2FsbERvdE5vZGU6OmlubGluZUV2YWx1YXRlICh0aGlzPTB4ZDI0YjlmZTAsIGV4ZWM9MHhi
ZmZmZTQxMCkgYXQgbm9kZXMuY3BwOjEyMjkKIzExIDB4MDA1ZGIzYjAgaW4gS0pTOjpGdW5jdGlv
bkNhbGxEb3ROb2RlOjpldmFsdWF0ZSAodGhpcz0weGQyNGI5ZmUwLCBleGVjPTB4YmZmZmU0MTAp
IGF0IG5vZGVzLmNwcDoxMjM0CiMxMiAweDAwNWNkNjQ3IGluIEtKUzo6RXhwclN0YXRlbWVudE5v
ZGU6OmV4ZWN1dGUgKHRoaXM9MHhkMjRiYmZlMCwgZXhlYz0weGJmZmZlNDEwKSBhdCBub2Rlcy5j
cHA6MzcyOAojMTMgMHgwMDVhZTY0OSBpbiBzdGF0ZW1lbnRMaXN0RXhlY3V0ZSAoc3RhdGVtZW50
cz1AMHhkMjRkZGVlMCwgZXhlYz0weGJmZmZlNDEwKSBhdCBub2Rlcy5jcHA6MzY4MQojMTQgMHgw
MDVhZTZkNiBpbiBLSlM6OkJsb2NrTm9kZTo6ZXhlY3V0ZSAodGhpcz0weGQyNGRkZWQwLCBleGVj
PTB4YmZmZmU0MTApIGF0IG5vZGVzLmNwcDozNzA2CiMxNSAweDAwNWJjNGQ0IGluIEtKUzo6RnVu
Y3Rpb25Cb2R5Tm9kZTo6ZXhlY3V0ZSAodGhpcz0weGQyNGRkZWQwLCBleGVjPTB4YmZmZmU0MTAp
IGF0IG5vZGVzLmNwcDo0NjIwCiMxNiAweDAwNWJjY2FjIGluIEtKUzo6RnVuY3Rpb25JbXA6OmNh
bGxBc0Z1bmN0aW9uICh0aGlzPTB4MThjNTBjMDAsIGV4ZWM9MHhkMjIyYmVmYywgdGhpc09iaj0w
eDE4YzUwMDAwLCBhcmdzPUAweGJmZmZlNGVjKSBhdCBmdW5jdGlvbi5jcHA6NzYKIzE3IDB4MDA1
YzY5MzIgaW4gS0pTOjpKU09iamVjdDo6Y2FsbCAodGhpcz0weDE4YzUwYzAwLCBleGVjPTB4ZDIy
MmJlZmMsIHRoaXNPYmo9MHgxOGM1MDAwMCwgYXJncz1AMHhiZmZmZTRlYykgYXQgb2JqZWN0LmNw
cDo5NgojMTggMHgwMjBhMjM5OSBpbiBXZWJDb3JlOjpTY2hlZHVsZWRBY3Rpb246OmV4ZWN1dGUg
KHRoaXM9MHhkMjVkZGZlMCwgd2luZG93PTB4MThjNTAwMDApIGF0IFdlYkNvcmUvYmluZGluZ3Mv
anMvU2NoZWR1bGVkQWN0aW9uLmNwcDo3NQojMTkgMHgwMjEzMzk3ZSBpbiBLSlM6OldpbmRvdzo6
dGltZXJGaXJlZCAodGhpcz0weDE4YzUwMDAwLCB0aW1lcj0weGQyNWRmZmQwKSBhdCBXZWJDb3Jl
L2JpbmRpbmdzL2pzL2tqc193aW5kb3cuY3BwOjE0NDUKIzIwIDB4MDIxMzM5ZjIgaW4gS0pTOjpE
T01XaW5kb3dUaW1lcjo6ZmlyZWQgKHRoaXM9MHhkMjVkZmZkMCkgYXQgV2ViQ29yZS9iaW5kaW5n
cy9qcy9ranNfd2luZG93LmNwcDoxNDgzCiMyMSAweDAyMGQ5NmI0IGluIFdlYkNvcmU6OlRpbWVy
QmFzZTo6ZmlyZVRpbWVycyAoZmlyZVRpbWU9MTIwNDU0NjU4NC43ODA4MjYxLCBmaXJpbmdUaW1l
cnM9QDB4YmZmZmU2N2MpIGF0IFdlYkNvcmUvcGxhdGZvcm0vVGltZXIuY3BwOjM0NwojMjIgMHgw
MjBkOTc1YyBpbiBXZWJDb3JlOjpUaW1lckJhc2U6OnNoYXJlZFRpbWVyRmlyZWQgKCkgYXQgV2Vi
Q29yZS9wbGF0Zm9ybS9UaW1lci5jcHA6MzY4CiMyMyAweDAyMGI1NDU4IGluIHRpbWVyRmlyZWQg
KCkgYXQgV2ViQ29yZS9wbGF0Zm9ybS9tYWMvU2hhcmVkVGltZXJNYWMuY3BwOjg0CiMyNCAweDky
OTBhYjVlIGluIENGUnVuTG9vcFJ1blNwZWNpZmljICgpCiMyNSAweDkyOTBhZDE4IGluIENGUnVu
TG9vcFJ1bkluTW9kZSAoKQojMjYgMHg5NDQzYjZhMCBpbiBSdW5DdXJyZW50RXZlbnRMb29wSW5N
b2RlICgpCiMyNyAweDk0NDNiNGI5IGluIFJlY2VpdmVOZXh0RXZlbnRDb21tb24gKCkKIzI4IDB4
OTQ0M2IzMmQgaW4gQmxvY2tVbnRpbE5leHRFdmVudE1hdGNoaW5nTGlzdEluTW9kZSAoKQojMjkg
MHg5MjBkYTdkOSBpbiBfRFBTTmV4dEV2ZW50ICgpCiMzMCAweDkyMGRhMDhlIGluIC1bTlNBcHBs
aWNhdGlvbiBuZXh0RXZlbnRNYXRjaGluZ01hc2s6dW50aWxEYXRlOmluTW9kZTpkZXF1ZXVlOl0g
KCkKIzMxIDB4MDAwMjQ0Y2YgaW4gLVtCcm93c2VyQXBwbGljYXRpb24gbmV4dEV2ZW50TWF0Y2hp
bmdNYXNrOnVudGlsRGF0ZTppbk1vZGU6ZGVxdWV1ZTpdIChzZWxmPTB4YjQwMjJmYTAsIF9jbWQ9
MHg5NDk3OWJlMCwgbWFzaz00Mjk0OTY3Mjk1LCBleHBpcmF0aW9uPTB4YmI4MzJmZjAsIG1vZGU9
MHhhMDJkYmIzMCwgZGVxdWV1ZT0xICdcMDAxJykgYXQgL1ZvbHVtZXMvRGF0YS9Ib21lL0RvY3Vt
ZW50cy9Xb3JrL1dlYktpdC1naXQvSW50ZXJuYWwvU2FmYXJpL21hYy9Ccm93c2VyQXBwbGljYXRp
b24ubToxODgKIzMyIDB4OTIwZDMwYzUgaW4gLVtOU0FwcGxpY2F0aW9uIHJ1bl0gKCkKIzMzIDB4
OTIwYTAzMGEgaW4gTlNBcHBsaWNhdGlvbk1haW4gKCkKIzM0IDB4MDAwYWM0ZDkgaW4gbWFpbiAo
YXJnYz0xLCBhcmd2PTB4YmZmZmY1YmMpIGF0IC9Wb2x1bWVzL0RhdGEvSG9tZS9Eb2N1bWVudHMv
V29yay9XZWJLaXQtZ2l0L0ludGVybmFsL1NhZmFyaS9tYWMvbWFpbi5tOjEzCg==
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>19503</attachid>
            <date>2008-03-03 14:18:17 -0800</date>
            <delta_ts>2008-03-03 14:23:24 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-17313-v1.patch</filename>
            <type>text/plain</type>
            <size>4666</size>
            <attacher name="Mark Rowe (bdash)">mrowe</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL0NoYW5nZUxvZyBiL0xheW91dFRlc3RzL0NoYW5nZUxv
ZwppbmRleCA0NDRiNGI3Li45MzE4M2I3IDEwMDY0NAotLS0gYS9MYXlvdXRUZXN0cy9DaGFuZ2VM
b2cKKysrIGIvTGF5b3V0VGVzdHMvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTMgQEAKKzIwMDgtMDMt
MDMgIE1hcmsgUm93ZSAgPG1yb3dlQGFwcGxlLmNvbT4KKworICAgICAgICBSZXZpZXdlZCBieSBO
T0JPRFkgKE9PUFMhKS4KKworICAgICAgICBUZXN0IGZvciBodHRwOi8vYnVncy53ZWJraXQub3Jn
L3Nob3dfYnVnLmNnaT9pZD0xNzMxMworICAgICAgICBCdWcgMTczMTM6IHF1ZXJ5U2VsZWN0b3JB
bGwoKSBjYXVzaW5nIGNyYXNoZXMgd2hlbiBjYWxsZWQgdmlhIGRvam8ucXVlcnkoKSB3cmFwcGVy
CisKKyAgICAgICAgKiBmYXN0L2RvbS9TZWxlY3RvckFQSS9idWctMTczMTMtZXhwZWN0ZWQudHh0
OiBBZGRlZC4KKyAgICAgICAgKiBmYXN0L2RvbS9TZWxlY3RvckFQSS9idWctMTczMTMuaHRtbDog
QWRkZWQuCisKIDIwMDgtMDMtMDIgIEtldmluIE9sbGl2aWVyICA8a2V2aW5vQHRoZW9sbGl2aWVy
cy5jb20+CiAKICAgICAgICAgUmV2aWV3ZWQgYnkgRGF2ZSBIeWF0dC4KZGlmZiAtLWdpdCBhL0xh
eW91dFRlc3RzL2Zhc3QvZG9tL1NlbGVjdG9yQVBJL2J1Zy0xNzMxMy1leHBlY3RlZC50eHQgYi9M
YXlvdXRUZXN0cy9mYXN0L2RvbS9TZWxlY3RvckFQSS9idWctMTczMTMtZXhwZWN0ZWQudHh0Cm5l
dyBmaWxlIG1vZGUgMTAwNjQ0CmluZGV4IDAwMDAwMDAuLjcxZGJlM2IKLS0tIC9kZXYvbnVsbAor
KysgYi9MYXlvdXRUZXN0cy9mYXN0L2RvbS9TZWxlY3RvckFQSS9idWctMTczMTMtZXhwZWN0ZWQu
dHh0CkBAIC0wLDAgKzEsMyBAQAorVGVzdCBjYXNlIGZvciBidWcgMTczMTMKKworVGhlIHRlc3Qg
aGFzIHBhc3NlZCBpZiByZWxvYWRpbmcgdGhlIHBhZ2UgZG9lcyBub3QgY3Jhc2guCmRpZmYgLS1n
aXQgYS9MYXlvdXRUZXN0cy9mYXN0L2RvbS9TZWxlY3RvckFQSS9idWctMTczMTMuaHRtbCBiL0xh
eW91dFRlc3RzL2Zhc3QvZG9tL1NlbGVjdG9yQVBJL2J1Zy0xNzMxMy5odG1sCm5ldyBmaWxlIG1v
ZGUgMTAwNjQ0CmluZGV4IDAwMDAwMDAuLjY5ZjZiZGQKLS0tIC9kZXYvbnVsbAorKysgYi9MYXlv
dXRUZXN0cy9mYXN0L2RvbS9TZWxlY3RvckFQSS9idWctMTczMTMuaHRtbApAQCAtMCwwICsxLDI1
IEBACis8c2NyaXB0IHR5cGU9InRleHQvamF2YXNjcmlwdCI+CisgICAgaWYgKHdpbmRvdy5sYXlv
dXRUZXN0Q29udHJvbGxlcikgeworICAgICAgICBsYXlvdXRUZXN0Q29udHJvbGxlci53YWl0VW50
aWxEb25lKCk7CisgICAgICAgIGxheW91dFRlc3RDb250cm9sbGVyLmR1bXBBc1RleHQoKTsKKyAg
ICB9CisKKyAgICB3aW5kb3cub25sb2FkID0gZnVuY3Rpb24oKSB7CisgICAgICAgIGZ1bmN0aW9u
IGRvUmVsb2FkKCkgeworICAgICAgICAgICAgd2luZG93LmxvY2F0aW9uID0gd2luZG93LmxvY2F0
aW9uICsgJz8nOworICAgICAgICB9CisKKyAgICAgICAgZnVuY3Rpb24gZG9RU0EoKSB7CisgICAg
ICAgICAgICBkb2N1bWVudC5xdWVyeVNlbGVjdG9yQWxsKCdoMTpmaXJzdC1jaGlsZCcpOworICAg
ICAgICAgICAgaWYgKHdpbmRvdy5sb2NhdGlvbi50b1N0cmluZygpLmluZGV4T2YoJz8nKSA8IDAp
CisgICAgICAgICAgICAgICAgd2luZG93LnNldFRpbWVvdXQoZG9SZWxvYWQsIDEwMCk7CisgICAg
ICAgICAgICBlbHNlIGlmICh3aW5kb3cubGF5b3V0VGVzdENvbnRyb2xsZXIpCisgICAgICAgICAg
ICAgICAgbGF5b3V0VGVzdENvbnRyb2xsZXIubm90aWZ5RG9uZSgpOworICAgICAgICB9CisKKyAg
ICAgICAgd2luZG93LnNldFRpbWVvdXQoZG9RU0EsIDEwMCk7CisgICAgfQorPC9zY3JpcHQ+Cis8
aDE+VGVzdCBjYXNlIGZvciA8YSBocmVmPSdodHRwOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVn
LmNnaT9pZD0xNzMxMyc+YnVnIDE3MzEzPC9hPjwvaDE+Cis8cD5UaGUgdGVzdCBoYXMgcGFzc2Vk
IGlmIHJlbG9hZGluZyB0aGUgcGFnZSBkb2VzIG5vdCBjcmFzaC48L3A+Cis8aW5wdXQgdHlwZT0i
aGlkZGVuIj4KZGlmZiAtLWdpdCBhL1dlYkNvcmUvQ2hhbmdlTG9nIGIvV2ViQ29yZS9DaGFuZ2VM
b2cKaW5kZXggMzk2MGFhNy4uNjEwZTJkNSAxMDA2NDQKLS0tIGEvV2ViQ29yZS9DaGFuZ2VMb2cK
KysrIGIvV2ViQ29yZS9DaGFuZ2VMb2cKQEAgLTEsMyArMSwyMiBAQAorMjAwOC0wMy0wMyAgTWFy
ayBSb3dlICA8bXJvd2VAYXBwbGUuY29tPgorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAo
T09QUyEpLgorCisgICAgICAgIEZpeCBodHRwOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNn
aT9pZD0xNzMxMworICAgICAgICBCdWcgMTczMTM6IHF1ZXJ5U2VsZWN0b3JBbGwoKSBjYXVzaW5n
IGNyYXNoZXMgd2hlbiBjYWxsZWQgdmlhIGRvam8ucXVlcnkoKSB3cmFwcGVyCisKKyAgICAgICAg
Tm9kZTo6cXVlcnlTZWxlY3RvciBhbmQgU2VsZWN0b3JOb2RlTGlzdCB3ZXJlIG5vdCBzdWZmaWNp
ZW50bHkgaW5pdGlhbGl6aW5nIHRoZSBDU1NTdHlsZVNlbGVjdG9yCisgICAgICAgIGJlZm9yZSB1
c2luZyBpdCB0byByZXNvbHZlIHN0eWxlcywgd2hpY2ggbGVhZCB0byBpdCBoYXZpbmcgYSBzdGFs
ZSBtX3N0eWxlIG1lbWJlciBpbiBzb21lIHNpdHVhdGlvbnMuCisgICAgICAgIFRoaXMgc3RhbGUg
bV9zdHlsZSBtZW1iZXIgcmVzdWx0ZWQgaW4gYSB3aWxkIHN0b3JlIHRoYXQgd291bGQgd3JpdGUg
b3ZlciB3aGF0ZXZlciBvYmplY3Qgbm93IHJlc2lkZWQKKyAgICAgICAgYXQgdGhlIGxvY2F0aW9u
IG1fc3R5bGUgcG9pbnRlZCB0by4KKworICAgICAgICBUZXN0OiBmYXN0L2RvbS9TZWxlY3RvckFQ
SS9idWctMTczMTMuaHRtbAorCisgICAgICAgICogZG9tL05vZGUuY3BwOgorICAgICAgICAoV2Vi
Q29yZTo6Tm9kZTo6cXVlcnlTZWxlY3Rvcik6IENhbGwgaW5pdEZvclN0eWxlUmVzb2x2ZSB0byBm
dXJ0aGVyIGluaXRpYWxpemUgdGhlIENTU1N0eWxlU2VsZWN0b3IuCisgICAgICAgICogZG9tL1Nl
bGVjdG9yTm9kZUxpc3QuY3BwOgorICAgICAgICAoV2ViQ29yZTo6U2VsZWN0b3JOb2RlTGlzdDo6
U2VsZWN0b3JOb2RlTGlzdCk6IERpdHRvLgorCiAyMDA4LTAzLTAyICBBbHAgVG9rZXIgIDxhbHBA
YXRva2VyLmNvbT4KIAogICAgICAgICBBbm90aGVyIGZpeCBmb3Igbm9uLWRhdGFiYXNlIGJ1aWxk
cyBhZnRlciBjaGFuZ2VzIGluIHIzMDMzMS4KZGlmZiAtLWdpdCBhL1dlYkNvcmUvZG9tL05vZGUu
Y3BwIGIvV2ViQ29yZS9kb20vTm9kZS5jcHAKaW5kZXggOGE1MmUwZS4uYTg3OTEzZCAxMDA2NDQK
LS0tIGEvV2ViQ29yZS9kb20vTm9kZS5jcHAKKysrIGIvV2ViQ29yZS9kb20vTm9kZS5jcHAKQEAg
LTEyMjIsNiArMTIyMiw3IEBAIFBhc3NSZWZQdHI8RWxlbWVudD4gTm9kZTo6cXVlcnlTZWxlY3Rv
cihjb25zdCBTdHJpbmcmIHNlbGVjdG9ycywgRXhjZXB0aW9uQ29kZSYKICAgICAgICAgaWYgKG4t
PmlzRWxlbWVudE5vZGUoKSkgewogICAgICAgICAgICAgRWxlbWVudCogZWxlbWVudCA9IHN0YXRp
Y19jYXN0PEVsZW1lbnQqPihuKTsKICAgICAgICAgICAgIHN0eWxlU2VsZWN0b3ItPmluaXRFbGVt
ZW50QW5kUHNldWRvU3RhdGUoZWxlbWVudCk7CisgICAgICAgICAgICBzdHlsZVNlbGVjdG9yLT5p
bml0Rm9yU3R5bGVSZXNvbHZlKHN0YXRpY19jYXN0PEVsZW1lbnQqPihuKSwgMCk7CiAgICAgICAg
ICAgICBmb3IgKENTU1NlbGVjdG9yKiBzZWxlY3RvciA9IHF1ZXJ5U2VsZWN0b3I7IHNlbGVjdG9y
OyBzZWxlY3RvciA9IHNlbGVjdG9yLT5uZXh0KCkpIHsKICAgICAgICAgICAgICAgICBpZiAoc3R5
bGVTZWxlY3Rvci0+Y2hlY2tTZWxlY3RvcihzZWxlY3RvcikpCiAgICAgICAgICAgICAgICAgICAg
IHJldHVybiBlbGVtZW50OwpkaWZmIC0tZ2l0IGEvV2ViQ29yZS9kb20vU2VsZWN0b3JOb2RlTGlz
dC5jcHAgYi9XZWJDb3JlL2RvbS9TZWxlY3Rvck5vZGVMaXN0LmNwcAppbmRleCAyMDE1YTBlLi40
ZTAxMmE0IDEwMDY0NAotLS0gYS9XZWJDb3JlL2RvbS9TZWxlY3Rvck5vZGVMaXN0LmNwcAorKysg
Yi9XZWJDb3JlL2RvbS9TZWxlY3Rvck5vZGVMaXN0LmNwcApAQCAtNDQsNiArNDQsNyBAQCBTZWxl
Y3Rvck5vZGVMaXN0OjpTZWxlY3Rvck5vZGVMaXN0KFBhc3NSZWZQdHI8Tm9kZT4gcm9vdE5vZGUs
IENTU1NlbGVjdG9yKiBxdWVyeQogICAgIGZvciAoTm9kZSogbiA9IHJvb3ROb2RlLT5maXJzdENo
aWxkKCk7IG47IG4gPSBuLT50cmF2ZXJzZU5leHROb2RlKHJvb3ROb2RlLmdldCgpKSkgewogICAg
ICAgICBpZiAobi0+aXNFbGVtZW50Tm9kZSgpKSB7CiAgICAgICAgICAgICBzdHlsZVNlbGVjdG9y
LT5pbml0RWxlbWVudEFuZFBzZXVkb1N0YXRlKHN0YXRpY19jYXN0PEVsZW1lbnQqPihuKSk7Cisg
ICAgICAgICAgICBzdHlsZVNlbGVjdG9yLT5pbml0Rm9yU3R5bGVSZXNvbHZlKHN0YXRpY19jYXN0
PEVsZW1lbnQqPihuKSwgMCk7CiAgICAgICAgICAgICBmb3IgKENTU1NlbGVjdG9yKiBzZWxlY3Rv
ciA9IHF1ZXJ5U2VsZWN0b3I7IHNlbGVjdG9yOyBzZWxlY3RvciA9IHNlbGVjdG9yLT5uZXh0KCkp
IHsKICAgICAgICAgICAgICAgICBpZiAoc3R5bGVTZWxlY3Rvci0+Y2hlY2tTZWxlY3RvcihzZWxl
Y3RvcikpIHsKICAgICAgICAgICAgICAgICAgICAgbV9ub2Rlcy5hcHBlbmQobik7Cg==
</data>
<flag name="review"
          id="8529"
          type_id="1"
          status="+"
          setter="mitz"
    />
          </attachment>
      

    </bug>

</bugzilla>