<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>22413</bug_id>
          
          <creation_ts>2008-11-21 14:25:19 -0800</creation_ts>
          <short_desc>REGRESSION (r38652): Google Code page crashes WebKit</short_desc>
          <delta_ts>2025-12-22 15:58:45 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>New Bugs</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://code.google.com/apis/ajaxlibs/documentation/</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>GoogleBug, NeedsReduction, Regression</keywords>
          <priority>P1</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Charles Ying">charles_ying</reporter>
          <assigned_to name="Gavin Barraclough">barraclough</assigned_to>
          <cc>858wildcat</cc>
    
    <cc>ap</cc>
    
    <cc>barraclough</cc>
    
    <cc>blessed22759</cc>
    
    <cc>dieter</cc>
    
    <cc>doggeral</cc>
    
    <cc>hbridge+bugzilla</cc>
    
    <cc>irony42</cc>
    
    <cc>jimoase</cc>
    
    <cc>josehenton13</cc>
    
    <cc>kai.conragan</cc>
    
    <cc>roncouver</cc>
    
    <cc>vorkbob</cc>
    
    <cc>Wout.Mertens</cc>
    
    <cc>zwarich</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>99700</commentid>
    <comment_count>0</comment_count>
    <who name="Charles Ying">charles_ying</who>
    <bug_when>2008-11-21 14:25:19 -0800</bug_when>
    <thetext>WebKit nightly r38654 crashes on the above web page.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99761</commentid>
    <comment_count>1</comment_count>
    <who name="Cameron Zwarich (cpst)">zwarich</who>
    <bug_when>2008-11-21 21:41:51 -0800</bug_when>
    <thetext>I can confirm this with a local debug build of r38680.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99764</commentid>
    <comment_count>2</comment_count>
    <who name="Cameron Zwarich (cpst)">zwarich</who>
    <bug_when>2008-11-21 22:40:49 -0800</bug_when>
    <thetext>I thought this might be a reparsing bug, but it works fine in r38635, the revision that introduced reparsing.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99765</commentid>
    <comment_count>3</comment_count>
    <who name="Cameron Zwarich (cpst)">zwarich</who>
    <bug_when>2008-11-21 23:18:30 -0800</bug_when>
    <thetext>I can verify that this regresses in r38652, the introduction of polymorphic caching of prototype accesses.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99770</commentid>
    <comment_count>4</comment_count>
      <attachid>25373</attachid>
    <who name="Gavin Barraclough">barraclough</who>
    <bug_when>2008-11-22 01:15:56 -0800</bug_when>
    <thetext>Created attachment 25373
Ooops</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99771</commentid>
    <comment_count>5</comment_count>
      <attachid>25373</attachid>
    <who name="Cameron Zwarich (cpst)">zwarich</who>
    <bug_when>2008-11-22 04:00:50 -0800</bug_when>
    <thetext>Comment on attachment 25373
Ooops

Add a reference to this bug in the ChangeLog, and add a reproducibly failing layout test for this situation to fast/js/pic. Assuming you do that, r=me.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99774</commentid>
    <comment_count>6</comment_count>
    <who name="Cameron Zwarich (cpst)">zwarich</who>
    <bug_when>2008-11-22 04:31:04 -0800</bug_when>
    <thetext>*** Bug 22408 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99874</commentid>
    <comment_count>7</comment_count>
    <who name="Cameron Zwarich (cpst)">zwarich</who>
    <bug_when>2008-11-23 21:31:31 -0800</bug_when>
    <thetext>Gavin, hopefully you can get around to making a test and landing this soon. This bug makes WebKit unusable for a lot of people.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99878</commentid>
    <comment_count>8</comment_count>
    <who name="Gavin Barraclough">barraclough</who>
    <bug_when>2008-11-23 22:01:50 -0800</bug_when>
    <thetext>Sending        JavaScriptCore/ChangeLog
Sending        JavaScriptCore/jit/JIT.cpp
Transmitting file data ..
Committed revision 38697.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99893</commentid>
    <comment_count>9</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 00:33:53 -0800</bug_when>
    <thetext>*** Bug 22438 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99895</commentid>
    <comment_count>10</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 00:34:00 -0800</bug_when>
    <thetext>*** Bug 22442 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99897</commentid>
    <comment_count>11</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 00:34:09 -0800</bug_when>
    <thetext>*** Bug 22445 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99899</commentid>
    <comment_count>12</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 00:34:14 -0800</bug_when>
    <thetext>*** Bug 22437 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99901</commentid>
    <comment_count>13</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 00:34:21 -0800</bug_when>
    <thetext>*** Bug 22446 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99903</commentid>
    <comment_count>14</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 00:34:27 -0800</bug_when>
    <thetext>*** Bug 22436 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99905</commentid>
    <comment_count>15</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 00:34:37 -0800</bug_when>
    <thetext>*** Bug 22435 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99909</commentid>
    <comment_count>16</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2008-11-24 01:35:09 -0800</bug_when>
    <thetext>(In reply to comment #8)
&gt; Sending        JavaScriptCore/ChangeLog
&gt; Sending        JavaScriptCore/jit/JIT.cpp

Can a test be added for this bug?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99934</commentid>
    <comment_count>17</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 03:15:31 -0800</bug_when>
    <thetext>*** Bug 22434 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99936</commentid>
    <comment_count>18</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 03:15:52 -0800</bug_when>
    <thetext>*** Bug 22424 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99938</commentid>
    <comment_count>19</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 03:16:01 -0800</bug_when>
    <thetext>*** Bug 22425 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99940</commentid>
    <comment_count>20</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 03:16:11 -0800</bug_when>
    <thetext>*** Bug 22422 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>99942</commentid>
    <comment_count>21</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-11-24 03:16:25 -0800</bug_when>
    <thetext>*** Bug 22427 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>25373</attachid>
            <date>2008-11-22 01:15:56 -0800</date>
            <delta_ts>2008-11-22 04:00:50 -0800</delta_ts>
            <desc>Ooops</desc>
            <filename>patch.oops.txt</filename>
            <type>text/plain</type>
            <size>984</size>
            <attacher name="Gavin Barraclough">barraclough</attacher>
            
              <data encoding="base64">SW5kZXg6IENoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBDaGFuZ2VMb2cJKHJldmlzaW9uIDM4Njkw
KQorKysgQ2hhbmdlTG9nCSh3b3JraW5nIGNvcHkpCkBAIC0xLDMgKzEsMTIgQEAKKzIwMDgtMTEt
MjIgIEdhdmluIEJhcnJhY2xvdWdoICA8YmFycmFjbG91Z2hAYXBwbGUuY29tPgorCisgICAgICAg
IFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIFJlcGxhY2UgYWNjaWRlbnRh
bGx5IGRlbGV0ZWQgaW1tZWRpYXRlIGNoZWNrIGZyb20gZ2V0IGJ5IGlkIGNoYWluIHRyYW1wb2xp
bmUuCisKKyAgICAgICAgKiBqaXQvSklULmNwcDoKKyAgICAgICAgKEpTQzo6SklUOjpwcml2YXRl
Q29tcGlsZUdldEJ5SWRDaGFpbik6CisKIDIwMDgtMTEtMjEgIEdhdmluIEJhcnJhY2xvdWdoICA8
YmFycmFjbG91Z2hAYXBwbGUuY29tPgogCiAgICAgICAgIFJldmlld2VkIGJ5IE9saXZlciBIdW50
LgpJbmRleDogaml0L0pJVC5jcHAKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gaml0L0pJVC5jcHAJKHJldmlzaW9u
IDM4NjkwKQorKysgaml0L0pJVC5jcHAJKHdvcmtpbmcgY29weSkKQEAgLTMzMTMsNiArMzMxMyw3
IEBAIHZvaWQgSklUOjpwcml2YXRlQ29tcGlsZUdldEJ5SWRDaGFpbihTdHIKIAogICAgIC8vIENo
ZWNrIGVheCBpcyBhbiBvYmplY3Qgb2YgdGhlIHJpZ2h0IFN0cnVjdHVyZS4KICAgICBfXyB0ZXN0
bF9pMzJyKEpTSW1tZWRpYXRlOjpUYWdNYXNrLCBYODY6OmVheCk7CisgICAgYnVja2V0c09mRmFp
bC5hcHBlbmQoX18gam5lKCkpOwogICAgIGJ1Y2tldHNPZkZhaWwuYXBwZW5kKGNoZWNrU3RydWN0
dXJlKFg4Njo6ZWF4LCBzdHJ1Y3R1cmUpKTsKIAogICAgIFN0cnVjdHVyZSogY3VyclN0cnVjdHVy
ZSA9IHN0cnVjdHVyZTsK
</data>
<flag name="review"
          id="11759"
          type_id="1"
          status="+"
          setter="zwarich"
    />
          </attachment>
      

    </bug>

</bugzilla>