Summary: | REGRESSION: Crash under JITCompiler::link while loading Gmail | ||
---|---|---|---|
Product: | WebKit | Reporter: | Ryosuke Niwa <rniwa> |
Component: | JavaScriptCore | Assignee: | Nobody <webkit-unassigned> |
Status: | RESOLVED FIXED | ||
Severity: | Critical | CC: | adam, cgarcia, csaavedra, fpizlo, ggaren, oliver, phiw2, sergio, vjaquez, vomitols, webkit-bug-importer, zan |
Priority: | P1 | Keywords: | InRadar, Regression |
Version: | 528+ (Nightly build) | ||
Hardware: | Unspecified | ||
OS: | Unspecified |
Description
Ryosuke Niwa
2013-08-15 15:32:16 PDT
This stack trace is not useful, because the crash happens on a different thread. In the future, please attach a complete crash log as a file. I can reproduce this, getting this crash: Thread 15 Crashed:: JSC Compilation Thread 0 com.apple.JavaScriptCore 0x000000010d89b3de WTFCrash + 62 1 com.apple.JavaScriptCore 0x000000010d8b1bb9 WTF::CrashOnOverflow::overflowed() + 9 2 com.apple.JavaScriptCore 0x000000010d76eb6a JSC::DFG::JITCompiler::link(JSC::LinkBuffer&) + 5514 3 com.apple.JavaScriptCore 0x000000010d903507 JSC::DFG::JITCompiler::linkFunction() + 103 4 com.apple.JavaScriptCore 0x000000010d909edb JSC::DFG::Plan::compileInThreadImpl(JSC::DFG::LongLivedState&) + 971 5 com.apple.JavaScriptCore 0x000000010d909986 JSC::DFG::Plan::compileInThread(JSC::DFG::LongLivedState&) + 214 6 com.apple.JavaScriptCore 0x000000010d924044 JSC::DFG::Worklist::runThread() + 500 7 com.apple.JavaScriptCore 0x000000010d60f88f WTF::wtfThreadEntryPoint(void*) + 15 8 libsystem_pthread.dylib 0x00007fff8bdb38a9 _pthread_body + 138 9 libsystem_pthread.dylib 0x00007fff8bdb373a _pthread_start + 137 10 libsystem_pthread.dylib 0x00007fff8bdb7fd9 thread_start + 13 *** Bug 119881 has been marked as a duplicate of this bug. *** Still crashing: ASSERTION FAILED: isInt32() /Volumes/Data/webkit/Source/JavaScriptCore/runtime/JSCJSValueInlines.h(409) : int32_t JSC::JSValue::asInt32() const 1 0x1031de450 WTFCrash 2 0x102ca4cd5 JSC::JSValue::asInt32() const 3 0x102e54b5a JSC::DFG::LazyJSValue::switchLookupValue() const 4 0x102e51647 JSC::DFG::JITCompiler::link(JSC::LinkBuffer&) 5 0x102e539a4 JSC::DFG::JITCompiler::linkFunction() 6 0x102e88aa9 JSC::DFG::Plan::compileInThreadImpl(JSC::DFG::LongLivedState&) 7 0x102e88497 JSC::DFG::Plan::compileInThread(JSC::DFG::LongLivedState&) 8 0x102f2476c JSC::DFG::Worklist::runThread() 9 0x102f238e5 JSC::DFG::Worklist::threadFunction(void*) 10 0x103223490 WTF::threadEntryPoint(void*) 11 0x103223e18 WTF::wtfThreadEntryPoint(void*) 12 0x7fff91c097a2 _pthread_start 13 0x7fff91bf61e1 thread_start Landed in http://trac.webkit.org/changeset/154419 *** Bug 120198 has been marked as a duplicate of this bug. *** |