<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>69897</bug_id>
          
          <creation_ts>2011-10-11 21:51:48 -0700</creation_ts>
          <short_desc>Layout tests crashing in DFG JIT code</short_desc>
          <delta_ts>2011-10-12 01:00:24 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Tools / Tests</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.6</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://build.webkit.org/results/SnowLeopard%20Intel%20Leaks/r97218%20(19479)/results.html</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>LayoutTestFailure, MakingBotsRed, Regression</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Simon Fraser (smfr)">simon.fraser</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>barraclough</cc>
    
    <cc>fpizlo</cc>
    
    <cc>ggaren</cc>
    
    <cc>oliver</cc>
    
    <cc>simon.fraser</cc>
    
    <cc>webkit.review.bot</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>482201</commentid>
    <comment_count>0</comment_count>
    <who name="Simon Fraser (smfr)">simon.fraser</who>
    <bug_when>2011-10-11 21:51:48 -0700</bug_when>
    <thetext>The following tests are crashing in com.apple.JavaScriptCore: JSC::DFG::JITCodeGenerator on the SnowLeopard leaks bot:

fast/canvas/webgl/tex-image-with-format-and-type.html: crash log (com.apple.JavaScriptCore: JSC::DFG::JITCodeGenerator::silentFillGPR(JSC::DFG::VirtualRegister, JSC::X86Registers::RegisterID, JSC::X86Registers::RegisterID) + 871)
fast/dom/prototype-inheritance-2.html: crash log (com.apple.JavaScriptCore: JSC::DFG::AbstractValue::clobberStructures() + 100)
fast/harness/results.html: crash log (com.apple.JavaScriptCore: JSC::DFG::JITCodeGenerator::silentFillGPR(JSC::DFG::VirtualRegister, JSC::X86Registers::RegisterID, JSC::X86Registers::RegisterID) + 871)
inspector/debugger/linkifier.html: crash log (com.apple.JavaScriptCore: JSC::DFG::JITCodeGenerator::silentFillGPR(JSC::DFG::VirtualRegister, JSC::X86Registers::RegisterID, JSC::X86Registers::RegisterID) + 871)
inspector/debugger/script-formatter.html: crash log (com.apple.JavaScriptCore: JSC::DFG::JITCodeGenerator::silentFillGPR(JSC::DFG::VirtualRegister, JSC::X86Registers::RegisterID, JSC::X86Registers::RegisterID) +</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482204</commentid>
    <comment_count>1</comment_count>
    <who name="Simon Fraser (smfr)">simon.fraser</who>
    <bug_when>2011-10-11 21:53:43 -0700</bug_when>
    <thetext>Most are an assertion in JITCodeGenerator::silentFillGPR:

http://build.webkit.org/results/SnowLeopard%20Intel%20Leaks/r97218%20(19479)/fast/canvas/webgl/tex-image-with-format-and-type-crash-log.txt</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482215</commentid>
    <comment_count>2</comment_count>
    <who name="Simon Fraser (smfr)">simon.fraser</who>
    <bug_when>2011-10-11 22:17:00 -0700</bug_when>
    <thetext>Also on http://build.webkit.org/results/Lion%20Intel%20Debug%20(WebKit2%20Tests)/r97221%20(1193)/results.html
fast/dom/prototype-inheritance-2.html
is asserting in JavaScriptCore: JSC::DFG::AbstractValue::clobberStructures() + 125)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482221</commentid>
    <comment_count>3</comment_count>
    <who name="Gavin Barraclough">barraclough</who>
    <bug_when>2011-10-11 22:30:07 -0700</bug_when>
    <thetext>The silentFillGPR regressions are likely my bad; clobberStructures is likely due to Filip&apos;s last change.

I&apos;ll revert my last patch to get the tree green &amp; investigate in the morning, Filip, I&apos;ll leave it up to you to choose whether you want to revert or to just land a fix.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482223</commentid>
    <comment_count>4</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2011-10-11 22:32:00 -0700</bug_when>
    <thetext>(In reply to comment #3)
&gt; The silentFillGPR regressions are likely my bad; clobberStructures is likely due to Filip&apos;s last change.
&gt; 
&gt; I&apos;ll revert my last patch to get the tree green &amp; investigate in the morning, Filip, I&apos;ll leave it up to you to choose whether you want to revert or to just land a fix.

I&apos;m trying to figure this out right now...</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482241</commentid>
    <comment_count>5</comment_count>
    <who name="Gavin Barraclough">barraclough</who>
    <bug_when>2011-10-11 23:09:16 -0700</bug_when>
    <thetext>The silentFillGPR change is reverted in 97235.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482251</commentid>
    <comment_count>6</comment_count>
      <attachid>110643</attachid>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2011-10-11 23:21:49 -0700</bug_when>
    <thetext>Created attachment 110643
the patch for fast/dom/prototype-inheritance-2</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482282</commentid>
    <comment_count>7</comment_count>
      <attachid>110643</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-10-12 01:00:20 -0700</bug_when>
    <thetext>Comment on attachment 110643
the patch for fast/dom/prototype-inheritance-2

Clearing flags on attachment: 110643

Committed r97240: &lt;http://trac.webkit.org/changeset/97240&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>482283</commentid>
    <comment_count>8</comment_count>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-10-12 01:00:24 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>110643</attachid>
            <date>2011-10-11 23:21:49 -0700</date>
            <delta_ts>2011-10-12 01:00:19 -0700</delta_ts>
            <desc>the patch for fast/dom/prototype-inheritance-2</desc>
            <filename>fixabsval_patch_1.diff</filename>
            <type>text/plain</type>
            <size>2087</size>
            <attacher name="Filip Pizlo">fpizlo</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9DaGFuZ2VMb2cKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkocmV2aXNpb24gOTcyMzYpCisrKyBTb3VyY2Uv
SmF2YVNjcmlwdENvcmUvQ2hhbmdlTG9nCSh3b3JraW5nIGNvcHkpCkBAIC0xLDMgKzEsMjIgQEAK
KzIwMTEtMTAtMTEgIEZpbGlwIFBpemxvICA8ZnBpemxvQGFwcGxlLmNvbT4KKworICAgICAgICBM
YXlvdXQgdGVzdHMgY3Jhc2hpbmcgaW4gREZHIEpJVCBjb2RlCisgICAgICAgIGh0dHBzOi8vYnVn
cy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD02OTg5NworCisgICAgICAgIFJldmlld2VkIGJ5
IE5PQk9EWSAoT09QUyEpLgorICAgICAgICAKKyAgICAgICAgQWJzdHJhY3QgdmFsdWUgZmlsdHJh
dGlvbiBkaWRuJ3QgdGFrZSBpbnRvIGFjY291bnQgY2FzZXMgd2hlcmUgYSBzdHJ1Y3R1cmUKKyAg
ICAgICAgc2V0IGZpbHRlciwgY29tYmluZWQgd2l0aCBwcmVkaWN0ZWQgdHlwZSBrbm93bGVkZ2Us
IGNvdWxkIGxlYWQgdG8gYSBzdHJvbmdlcgorICAgICAgICBmaWx0ZXIgZm9yIHRoZSBzdHJ1Y3R1
cmUgYWJzdHJhY3QgdmFsdWUuCisgICAgICAgIAorICAgICAgICBUaGlzIGJ1ZyB3b3VsZCBoYXZl
IGJlZW4gYmVuaWduIGluIHJlbGVhc2UgYnVpbGRzOyBpdCB3b3VsZCBoYXZlIGp1c3QgbWVhbnQK
KyAgICAgICAgdGhhdCB0aGUgYW5hbHlzaXMgd2FzIGxlc3MgcHJlY2lzZSBhbmQgc29tZSBvcHRp
bWl6YXRpb24gb3Bwb3J0dW5pdGllcyB3b3VsZAorICAgICAgICBiZSBtaXNzZWQuIEkgaGF2ZSBh
biBBU1NFUlQgdGhhdCBpcyBtZWFudCB0byBjYXRjaCBzdWNoIGNhc2VzLCBhbmQgaXQgd2FzCisg
ICAgICAgIHRyaWdnZXJpbmcgc3BvcmFkaWNhbGx5IGluIG9uZSBvZiB0aGUgTGF5b3V0VGVzdHMu
CisKKyAgICAgICAgKiBkZmcvREZHQWJzdHJhY3RWYWx1ZS5oOgorICAgICAgICAoSlNDOjpERkc6
OkFic3RyYWN0VmFsdWU6OmZpbHRlcik6CisKIDIwMTEtMTAtMTEgIEdhdmluIEJhcnJhY2xvdWdo
ICA8YmFyYWNsb3VnaEBhcHBsZS5jb20+CiAKICAgICAgICAgVW5yZXZpZXdlZCwgdGVtcG9yYXJp
bHkgcmV2ZXJ0ZWQgcjk3MjE2IGR1ZSB0byBidWcgIzY5ODk3LgpJbmRleDogU291cmNlL0phdmFT
Y3JpcHRDb3JlL2RmZy9ERkdBYnN0cmFjdFZhbHVlLmgKPT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291cmNlL0ph
dmFTY3JpcHRDb3JlL2RmZy9ERkdBYnN0cmFjdFZhbHVlLmgJKHJldmlzaW9uIDk3MjM1KQorKysg
U291cmNlL0phdmFTY3JpcHRDb3JlL2RmZy9ERkdBYnN0cmFjdFZhbHVlLmgJKHdvcmtpbmcgY29w
eSkKQEAgLTQwMiw2ICs0MDIsMTMgQEAgc3RydWN0IEFic3RyYWN0VmFsdWUgewogICAgIHsKICAg
ICAgICAgbV90eXBlICY9IG90aGVyLnByZWRpY3Rpb25Gcm9tU3RydWN0dXJlcygpOwogICAgICAg
ICBtX3N0cnVjdHVyZS5maWx0ZXIob3RoZXIpOworICAgICAgICAKKyAgICAgICAgLy8gSXQncyBw
b3NzaWJsZSB0aGF0IHByaW9yIHRvIHRoZSBhYm92ZSB0d28gc3RhdGVtZW50cyB3ZSBoYWQgKEZv
bywgVE9QKSwgd2hlcmUKKyAgICAgICAgLy8gRm9vIGlzIGEgUHJlZGljdGVkVHlwZSB0aGF0IGlz
IGRpc2pvaW50IHdpdGggdGhlIHBhc3NlZCBTdHJ1Y3R1cmVTZXQuIEluIHRoYXQKKyAgICAgICAg
Ly8gY2FzZSwgd2Ugd2lsbCBub3cgaGF2ZSAoTm9uZSwgW3NvbWVTdHJ1Y3R1cmVdKS4gSW4gZ2Vu
ZXJhbCwgd2UgbmVlZCB0byBtYWtlCisgICAgICAgIC8vIHN1cmUgdGhhdCBuZXcgaW5mb3JtYXRp
b24gZ2xlYW5lZCBmcm9tIHRoZSBQcmVkaWN0ZWRUeXBlIG5lZWRzIHRvIGJlIGZlZCBiYWNrCisg
ICAgICAgIC8vIGludG8gdGhlIGluZm9ybWF0aW9uIGdsZWFuZWQgZnJvbSB0aGUgU3RydWN0dXJl
U2V0LgorICAgICAgICBtX3N0cnVjdHVyZS5maWx0ZXIobV90eXBlKTsKICAgICB9CiAgICAgCiAg
ICAgdm9pZCBmaWx0ZXIoUHJlZGljdGVkVHlwZSB0eXBlKQo=
</data>

          </attachment>
      

    </bug>

</bugzilla>