<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>20391</bug_id>
          
          <creation_ts>2008-08-14 22:52:38 -0700</creation_ts>
          <short_desc>REGRESSION (r35417-r35531): Crash in Machine.cpp:1838 when leaving GAFYD GMail</short_desc>
          <delta_ts>2008-08-22 21:05:20 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>JavaScriptCore</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Mac (Intel)</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar, Regression</keywords>
          <priority>P1</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ian &apos;Hixie&apos; Hickson">ian</reporter>
          <assigned_to name="Cameron Zwarich (cpst)">zwarich</assigned_to>
          <cc>ap</cc>
    
    <cc>aroben</cc>
    
    <cc>mrowe</cc>
    
    <cc>oliver</cc>
    
    <cc>zwarich</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>88533</commentid>
    <comment_count>0</comment_count>
    <who name="Ian &apos;Hixie&apos; Hickson">ian</who>
    <bug_when>2008-08-14 22:52:38 -0700</bug_when>
    <thetext>STEPS TO REPRODUCE
1. Log in to Google Apps For Your Domain GMail
2. Reload, navigate away, or otherwise cause the page to unload.

ACTUAL RESULTS
Crash.

Exception Type:  EXC_BAD_ACCESS (SIGBUS)
Exception Codes: KERN_PROTECTION_FAILURE at 0x0000000000000004

Stack trace: http://pastebin.com/f51ea9e1d

&lt;bdash&gt; Machine.cpp:1838 is where the crash is happening</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88534</commentid>
    <comment_count>1</comment_count>
    <who name="Geoffrey Garen">ggaren</who>
    <bug_when>2008-08-14 22:55:55 -0700</bug_when>
    <thetext>Very similar to https://bugs.webkit.org/show_bug.cgi?id=20386.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88535</commentid>
    <comment_count>2</comment_count>
    <who name="Ian &apos;Hixie&apos; Hickson">ian</who>
    <bug_when>2008-08-14 22:56:08 -0700</bug_when>
    <thetext>Doesn&apos;t crash in r35417
Does crash in r35531</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88536</commentid>
    <comment_count>3</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-08-14 23:15:46 -0700</bug_when>
    <thetext>Line 1838 is:

        r[dst] = scope-&gt;registerAt(index);

The disassembly indicates that the crash is due to &quot;scope&quot; being 0.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88545</commentid>
    <comment_count>4</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-08-15 04:37:13 -0700</bug_when>
    <thetext>&lt;rdar://problem/6152195&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88639</commentid>
    <comment_count>5</comment_count>
    <who name="Cameron Zwarich (cpst)">zwarich</who>
    <bug_when>2008-08-16 14:30:57 -0700</bug_when>
    <thetext>This is a reproducible crash, so it should be P1. I am also assigning it to myself.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88666</commentid>
    <comment_count>6</comment_count>
    <who name="Cameron Zwarich (cpst)">zwarich</who>
    <bug_when>2008-08-17 04:00:50 -0700</bug_when>
    <thetext>Since this seems so similar to bug 20386, it seems like the regression is caused by r35445, but I have no way of testing myself. I&apos;ll try to fix bug 20386, and see if the fix also works for this bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>88694</commentid>
    <comment_count>7</comment_count>
    <who name="Oliver Hunt">oliver</who>
    <bug_when>2008-08-17 16:43:35 -0700</bug_when>
    <thetext>bug 20386 is now fixed (r35812) so this may be fixed. Hixie can you check?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>89159</commentid>
    <comment_count>8</comment_count>
    <who name="Cameron Zwarich (cpst)">zwarich</who>
    <bug_when>2008-08-22 21:05:20 -0700</bug_when>
    <thetext>Ian said that this was indeed fixed.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>