<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>21182</bug_id>
          
          <creation_ts>2008-09-27 15:04:41 -0700</creation_ts>
          <short_desc>REGRESSION(r36982): Reproducible crash running fast/loader/frame-creation-removal.html</short_desc>
          <delta_ts>2008-09-27 15:18:30 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>New Bugs</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>NeedsReduction, Regression</keywords>
          <priority>P1</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Mark Rowe (bdash)">mrowe</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>hyatt</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>93079</commentid>
    <comment_count>0</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-09-27 15:04:41 -0700</bug_when>
    <thetext>This was introduced by &lt;http://trac.webkit.org/changeset/36982&gt;.  See the second crash log entry in &lt;http://build.webkit.org/results/trunk-mac-ppc-release/14838/DumpRenderTree.crash.log&gt;:

Exception:  EXC_BAD_ACCESS (0x0001)
Codes:      KERN_PROTECTION_FAILURE (0x0002) at 0x00000000

Thread 0 Crashed:
0   com.apple.WebKit         	0x003d8db4 WebFrameLoaderClient::createFrame(WebCore::KURL const&amp;, WebCore::String const&amp;, WebCore::HTMLFrameOwnerElement*, WebCore::String const&amp;, bool, int, int) + 372 (WebFrameLoaderClient.mm:1090)
1   com.apple.WebCore        	0x0119a97c WebCore::FrameLoader::loadSubframe(WebCore::HTMLFrameOwnerElement*, WebCore::KURL const&amp;, WebCore::String const&amp;, WebCore::String const&amp;) + 396 (RefPtr.h:50)
2   com.apple.WebCore        	0x0119c31c WebCore::FrameLoader::requestFrame(WebCore::HTMLFrameOwnerElement*, WebCore::String const&amp;, WebCore::AtomicString const&amp;) + 876 (FrameLoader.cpp:445)
3   com.apple.WebCore        	0x011c7a54 WebCore::HTMLFrameElementBase::openURL() + 260 (HTMLFrameElementBase.cpp:106)
4   com.apple.WebCore        	0x011c7c48 WebCore::HTMLFrameElementBase::setNameAndOpenURL() + 440 (HTMLFrameElementBase.cpp:162)
5   com.apple.WebCore        	0x010a8374 WebCore::ContainerNode::dispatchPostAttachCallbacks() + 84 (ContainerNode.cpp:568)
6   com.apple.WebCore        	0x010a845c WebCore::ContainerNode::attach() + 140 (ContainerNode.cpp:588)
7   com.apple.WebCore        	0x01156a48 WebCore::Element::attach() + 40 (Element.cpp:662)
8   com.apple.WebCore        	0x011c7138 WebCore::HTMLFrameElementBase::attach() + 72 (Node.h:367)
9   com.apple.WebCore        	0x011cb948 WebCore::HTMLIFrameElement::attach() + 24 (Node.h:367)
10  com.apple.WebCore        	0x010a76c4 WebCore::ContainerNode::appendChild(WTF::PassRefPtr&lt;WebCore::Node&gt;, int&amp;, bool) + 564 (ContainerNode.cpp:506)
11  com.apple.WebCore        	0x013038d0 WebCore::JSNode::appendChild(JSC::ExecState*, JSC::ArgList const&amp;) + 128 (JSNodeCustom.cpp:102)
12  com.apple.JavaScriptCore 	0x002b7074 JSC::Machine::privateExecute(JSC::Machine::ExecutionFlag, JSC::ExecState*, JSC::RegisterFile*, JSC::Register*, JSC::ScopeChainNode*, JSC::JSValue**) + 39732 (Machine.cpp:3326)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>93083</commentid>
    <comment_count>1</comment_count>
    <who name="Dave Hyatt">hyatt</who>
    <bug_when>2008-09-27 15:18:30 -0700</bug_when>
    <thetext>Fixed in r37011.
</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>