Summary: | REGRESSION (r38652): Google Code page crashes WebKit | ||||||
---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Charles Ying <charles_ying> | ||||
Component: | New Bugs | Assignee: | Gavin Barraclough <barraclough> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | Normal | CC: | 858wildcat, ap, barraclough, dieter, doggeral, hbridge+bugzilla, irony42, jimoase, josehenton13, kai.conragan, roncouver, vorkbob, Wout.Mertens, zwarich | ||||
Priority: | P1 | Keywords: | GoogleBug, NeedsReduction, Regression | ||||
Version: | 528+ (Nightly build) | ||||||
Hardware: | Mac | ||||||
OS: | OS X 10.5 | ||||||
URL: | http://code.google.com/apis/ajaxlibs/documentation/ | ||||||
Attachments: |
|
Description
Charles Ying
2008-11-21 14:25:19 PST
I can confirm this with a local debug build of r38680. I thought this might be a reparsing bug, but it works fine in r38635, the revision that introduced reparsing. I can verify that this regresses in r38652, the introduction of polymorphic caching of prototype accesses. Created attachment 25373 [details]
Ooops
Comment on attachment 25373 [details]
Ooops
Add a reference to this bug in the ChangeLog, and add a reproducibly failing layout test for this situation to fast/js/pic. Assuming you do that, r=me.
*** Bug 22408 has been marked as a duplicate of this bug. *** Gavin, hopefully you can get around to making a test and landing this soon. This bug makes WebKit unusable for a lot of people. Sending JavaScriptCore/ChangeLog Sending JavaScriptCore/jit/JIT.cpp Transmitting file data .. Committed revision 38697. *** Bug 22438 has been marked as a duplicate of this bug. *** *** Bug 22442 has been marked as a duplicate of this bug. *** *** Bug 22445 has been marked as a duplicate of this bug. *** *** Bug 22437 has been marked as a duplicate of this bug. *** *** Bug 22446 has been marked as a duplicate of this bug. *** *** Bug 22436 has been marked as a duplicate of this bug. *** *** Bug 22435 has been marked as a duplicate of this bug. *** (In reply to comment #8) > Sending JavaScriptCore/ChangeLog > Sending JavaScriptCore/jit/JIT.cpp Can a test be added for this bug? *** Bug 22434 has been marked as a duplicate of this bug. *** *** Bug 22424 has been marked as a duplicate of this bug. *** *** Bug 22425 has been marked as a duplicate of this bug. *** *** Bug 22422 has been marked as a duplicate of this bug. *** *** Bug 22427 has been marked as a duplicate of this bug. *** |