Bug 4284

Summary: REGRESSION: Javascript attempt to access non-existent array elements crashes
Product: WebKit Reporter: Kevin Broderick <kbroderick>
Component: JavaScriptCoreAssignee: Maciej Stachowiak <mjs>
Status: RESOLVED FIXED    
Severity: Critical CC: mrowe
Priority: P2    
Version: 420+   
Hardware: Mac   
OS: OS X 10.4   
URL: http://online.wsj.com/public/article/0,,SB112311985732004654-x3qD8ODU_jwTvTplbvV6uhXfyBc_20060803,00.html?mod=blogs
Attachments:
Description Flags
Reduction
none
Reduction wrapped in HTML for easy testing none

Description Kevin Broderick 2005-08-04 11:52:03 PDT
The headerscript.js included on the given URL from the Wall Street Journal online edition causes a crash 
on ToT as of 4 Aug 2005, but not on WebKit released with Tiger.  This appears to be due to the attempt 
to access the output of GetCookie(N) with the line "var crumbs = .... "; assigning an empty string to a 
variable and then attempting to access it in a similar manner causes the same crash.  Stack trace below; 
regression attached.


Host Name:      titaniumbook
Date/Time:      2005-08-04 14:41:54.063 -0400
OS Version:     10.4.2 (Build 8C46)
Report Version: 3

Command: Safari
Path:    /Applications/Safari.app/Contents/MacOS/Safari
Parent:  bash [10094]

Version:        2.0 (412.2)
Build Version:  1
Project Name:   WebBrowser
Source Version: 4120200

PID:    15911
Thread: 0

Exception:  EXC_BAD_ACCESS (0x0001)
Codes:      KERN_PROTECTION_FAILURE (0x0002) at 0x00000000

Thread 0 Crashed:
0   com.apple.JavaScriptCore 	0x0105f53c KJS::ValueImp::dispatchToBoolean(KJS::ExecState*) const + 
24 (value.h:467)
1   com.apple.JavaScriptCore 	0x010272dc KJS::ConditionalNode::evaluate(KJS::ExecState*) + 136 
(nodes.cpp:1355)
2   com.apple.JavaScriptCore 	0x0101eea4 KJS::AssignExprNode::evaluate(KJS::ExecState*) + 44 
(nodes.cpp:1591)
3   com.apple.JavaScriptCore 	0x01026bc4 KJS::VarDeclNode::evaluate(KJS::ExecState*) + 112 
(nodes.cpp:1623)
4   com.apple.JavaScriptCore 	0x01026ad8 KJS::VarDeclListNode::evaluate(KJS::ExecState*) + 76 
(nodes.cpp:1694)
5   com.apple.JavaScriptCore 	0x010269a4 KJS::VarStatementNode::execute(KJS::ExecState*) + 108 
(nodes.cpp:1727)
6   com.apple.JavaScriptCore 	0x010247b8 KJS::SourceElementsNode::execute(KJS::ExecState*) + 428 
(nodes.cpp:2924)
7   com.apple.JavaScriptCore 	0x01021f64 KJS::BlockNode::execute(KJS::ExecState*) + 132 (nodes.cpp:
1773)
8   com.apple.JavaScriptCore 	0x0101ba3c KJS::InterpreterImp::evaluate(KJS::UString const&, KJS::Value 
const&, KJS::UString const&, int) + 844 (internal.cpp:814)
9   com.apple.JavaScriptCore 	0x0101c458 KJS::Interpreter::evaluate(KJS::UString const&, int, 
KJS::UString const&, KJS::Value const&) + 64 (interpreter.cpp:128)
10  com.apple.WebCore        	0x01652f2c KJSProxyImpl::evaluate(QString, int, QString const&, 
DOM::NodeImpl*) + 196 (kjs_proxy.cpp:121)
11  com.apple.WebCore        	0x0160b9dc KHTMLPart::executeScript(QString, int, DOM::NodeImpl*, 
QString const&) + 152 (khtml_part.cpp:5293)
12  com.apple.WebCore        	0x0168db8c khtml::HTMLTokenizer::scriptExecution(QString const&, 
QString, int) + 220 (htmltokenizer.cpp:621)
13  com.apple.WebCore        	0x0168ddec khtml::HTMLTokenizer::notifyFinished
(khtml::CachedObject*) + 312 (htmltokenizer.cpp:2028)
14  com.apple.WebCore        	0x01692f18 khtml::CachedScript::checkNotify() + 84 (loader.cpp:323)
15  com.apple.WebCore        	0x016959a4 khtml::CachedScript::data(QBuffer&, bool) + 192 
(loader.cpp:314)
16  com.apple.WebCore        	0x016950b8 khtml::Loader::slotFinished(KIO::Job*, NSData*) + 444 
(loader.cpp:1638)
17  com.apple.WebCore        	0x016eac58 KWQSignal::callWithData(KIO::Job*, NSData*) const + 136 
(KWQSignal.mm:182)
18  com.apple.WebCore        	0x016f25d4 -[KWQResourceLoader finishJobAndHandle:] + 84 
(KWQResourceLoader.mm:94)
19  com.apple.WebKit         	0x003240fc -[WebSubresourceLoader didFinishLoading] + 84 
(WebSubresourceLoader.m:190)
20  com.apple.WebKit         	0x0032c194 -[WebLoader connectionDidFinishLoading:] + 52 
(WebLoader.m:651)
21  com.apple.Foundation     	0x928af73c -[NSURLConnection(NSURLConnectionInternal) 
_sendDidFinishLoadingCallback] + 72
22  com.apple.Foundation     	0x928ad9f0 -[NSURLConnection(NSURLConnectionInternal) 
_sendCallbacks] + 508
23  com.apple.Foundation     	0x928ad778 _sendCallbacks + 156
24  com.apple.CoreFoundation 	0x9074bd2c __CFRunLoopDoSources0 + 384
25  com.apple.CoreFoundation 	0x9074b25c __CFRunLoopRun + 452
26  com.apple.CoreFoundation 	0x9074acdc CFRunLoopRunSpecific + 268
27  com.apple.Foundation     	0x9288bec4 -[NSRunLoop runMode:beforeDate:] + 172
28  com.apple.Foundation     	0x928d0c4c -[NSRunLoop runUntilDate:] + 80
29  com.apple.AppKit         	0x93889ee0 NSCoreDragReceiveProc + 1012
30  com.apple.HIServices     	0x917aea0c DoDropMessage + 96
31  com.apple.HIServices     	0x917afeb0 CoreDragMessageHandler + 1332
32  com.apple.CoreFoundation 	0x90792610 __CFMessagePortPerform + 304
33  com.apple.CoreFoundation 	0x90758f94 __CFRunLoopDoSource1 + 152
34  com.apple.CoreFoundation 	0x9074b6ac __CFRunLoopRun + 1556
35  com.apple.CoreFoundation 	0x9074acdc CFRunLoopRunSpecific + 268
36  com.apple.HIToolbox      	0x93123be0 RunCurrentEventLoopInMode + 264
37  com.apple.HIToolbox      	0x93123274 ReceiveNextEventCommon + 380
38  com.apple.HIToolbox      	0x931230e0 BlockUntilNextEventMatchingListInMode + 96
39  com.apple.AppKit         	0x9362c1a4 _DPSNextEvent + 384
40  com.apple.AppKit         	0x9362be68 -[NSApplication 
nextEventMatchingMask:untilDate:inMode:dequeue:] + 116
41  com.apple.Safari         	0x00007058 0x1000 + 24664
42  com.apple.AppKit         	0x936283cc -[NSApplication run] + 472
43  com.apple.AppKit         	0x93718c1c NSApplicationMain + 452
44  com.apple.Safari         	0x00002700 0x1000 + 5888
45  com.apple.Safari         	0x00057190 0x1000 + 352656

Thread 1:
0   libSystem.B.dylib        	0x9000a778 mach_msg_trap + 8
1   libSystem.B.dylib        	0x9000a6bc mach_msg + 60
2   com.apple.CoreFoundation 	0x9074b3d8 __CFRunLoopRun + 832
3   com.apple.CoreFoundation 	0x9074acdc CFRunLoopRunSpecific + 268
4   com.apple.Foundation     	0x9288bec4 -[NSRunLoop runMode:beforeDate:] + 172
5   com.apple.Foundation     	0x9288bdfc -[NSRunLoop run] + 76
6   com.apple.WebKit         	0x0036779c +[WebFileDatabase _syncLoop:] + 176 
(WebFileDatabase.m:295)
7   com.apple.Foundation     	0x9287cf34 forkThreadForFunction + 108
8   libSystem.B.dylib        	0x9002c3d4 _pthread_body + 96

Thread 2:
0   libSystem.B.dylib        	0x9000a778 mach_msg_trap + 8
1   libSystem.B.dylib        	0x9000a6bc mach_msg + 60
2   com.apple.CoreFoundation 	0x9074b3d8 __CFRunLoopRun + 832
3   com.apple.CoreFoundation 	0x9074acdc CFRunLoopRunSpecific + 268
4   com.apple.Foundation     	0x928a43e0 +[NSURLConnection(NSURLConnectionInternal) 
_resourceLoadLoop:] + 264
5   com.apple.Foundation     	0x9287cf34 forkThreadForFunction + 108
6   libSystem.B.dylib        	0x9002c3d4 _pthread_body + 96

Thread 3:
0   libSystem.B.dylib        	0x9000a778 mach_msg_trap + 8
1   libSystem.B.dylib        	0x9000a6bc mach_msg + 60
2   com.apple.CoreFoundation 	0x9074b3d8 __CFRunLoopRun + 832
3   com.apple.CoreFoundation 	0x9074acdc CFRunLoopRunSpecific + 268
4   com.apple.Foundation     	0x928a5520 +[NSURLCache _diskCacheSyncLoop:] + 152
5   com.apple.Foundation     	0x9287cf34 forkThreadForFunction + 108
6   libSystem.B.dylib        	0x9002c3d4 _pthread_body + 96

Thread 4:
0   libSystem.B.dylib        	0x9002ca98 semaphore_wait_signal_trap + 8
1   libSystem.B.dylib        	0x9003127c pthread_cond_wait + 508
2   com.apple.Foundation     	0x928840a0 -[NSConditionLock lockWhenCondition:] + 68
3   com.apple.Syndication    	0x9b02bab0 -[AsyncDB _run:] + 192
4   com.apple.Foundation     	0x9287cf34 forkThreadForFunction + 108
5   libSystem.B.dylib        	0x9002c3d4 _pthread_body + 96

Thread 0 crashed with PPC Thread State 64:
  srr0: 0x000000000105f53c srr1: 0x000000000200f030                        vrsave: 
0x0000000000000000
    cr: 0x84024248          xer: 0x0000000000000007   lr: 0x00000000010272dc  ctr: 
0x000000000105f524
    r0: 0x0000000000000000   r1: 0x00000000bfffc750   r2: 0x00000000000001a0   r3: 
0x0000000000000000
    r4: 0x00000000bfffcb18   r5: 0x00000000bfffcb18   r6: 0x00000000bfffc62c   r7: 
0x00000000010da05c
    r8: 0x000000000b363c20   r9: 0x0000000000000007  r10: 0x0000000001037b20  r11: 
0x000000008fe519e0
   r12: 0x000000000105f524  r13: 0x0000000000000000  r14: 0x0000000000000001  r15: 
0x0000000000000000
   r16: 0x0000000000000001  r17: 0x0000000000000000  r18: 0x0000000000000000  r19: 
0x0000000000000000
   r20: 0x0000000000000000  r21: 0x0000000000000000  r22: 0x0000000009bb0440  r23: 
0x00000000bfffcd78
   r24: 0x00000000bfffcc84  r25: 0x00000000bfffcb0c  r26: 0x00000000bfffc9f8  r27: 
0x00000000bfffc928
   r28: 0x00000000bfffc848  r29: 0x000000000b363b08  r30: 0x00000000bfffcb18  r31: 
0x0000000001027264

Binary Images Description:
    0x1000 -    0xd7fff com.apple.Safari 2.0 (412.2)	/Applications/Safari.app/Contents/MacOS/Safari
  0x305000 -   0x3a0fff com.apple.WebKit 412+	/Users/kbroderick/Documents/src/builds/
Deployment/WebKit.framework/Versions/A/WebKit
  0x6bf000 -   0x6c0fff net.culater.SIMBL 0.2 (6)	/Library/InputManagers/SIMBL/SIMBL.bundle/
Contents/MacOS/SIMBL
  0x6c4000 -   0x6c4fff jp.hetima.SafariStand.loader SafariStand-loader version  1.0 (5)
	/Users/kbroderick/Library/InputManagers/SafariStand/SafariStand-loader.bundle/Contents/
MacOS/SafariStand-loader
  0x6d8000 -   0x6dafff com.ocdev.taboo ??? (0.3)	/Library/Application Support/SIMBL/Plugins/
Taboo.bundle/Contents/MacOS/Taboo
 0x1008000 -  0x10cbfff com.apple.JavaScriptCore 412.1	/Users/kbroderick/Documents/src/
builds/Deployment/JavaScriptCore.framework/Versions/A/JavaScriptCore
 0x15b7000 -  0x17d7fff com.apple.WebCore 413.1	/Users/kbroderick/Documents/src/builds/
Deployment/WebCore.framework/Versions/A/WebCore
 0x6ee5000 -  0x6f19fff jp.hetima.SafariStand 2.0b3 (107)	/Users/kbroderick/Library/
InputManagers/SafariStand/SafariStand.bundle/Contents/MacOS/SafariStand
 0xb905000 -  0xb90bfff com.apple.DictionaryServiceComponent 1.0.0
	/System/Library/Components/DictionaryService.component/Contents/MacOS/DictionaryService
 0xb964000 -  0xba40fff com.divxnetworks.DivXCodec 5.1.1	/Library/QuickTime/DivX 5.component/
Contents/MacOS/DivX 5
0x32000000 - 0x32023fff isao.sonobe.OgreKit OgreKit version 1.2.2 (1.2.3)
	/Users/kbroderick/Library/InputManagers/SafariStand/SafariStand.bundle/Contents/Resources/
OgreKit.framework/OgreKit
0x8fe00000 - 0x8fe51fff dyld 43.1	/usr/lib/dyld
0x90000000 - 0x901a6fff libSystem.B.dylib 	/usr/lib/libSystem.B.dylib
0x901fe000 - 0x90202fff libmathCommon.A.dylib 	/usr/lib/system/libmathCommon.A.dylib
0x90204000 - 0x90257fff com.apple.CoreText 1.0.0 (???)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/CoreText.framework/Versions/A/CoreText
0x90284000 - 0x90335fff ATS 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ATS.framework/Versions/A/ATS
0x90364000 - 0x9069dfff com.apple.CoreGraphics 1.256.14 (???)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
CoreGraphics.framework/Versions/A/CoreGraphics
0x90728000 - 0x90801fff com.apple.CoreFoundation 6.4.2 (368.11)
	/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
0x9084a000 - 0x9084afff com.apple.CoreServices 10.4 (???)	/System/Library/Frameworks/
CoreServices.framework/Versions/A/CoreServices
0x9084c000 - 0x9094efff libicucore.A.dylib 	/usr/lib/libicucore.A.dylib
0x909a8000 - 0x90a2cfff libobjc.A.dylib 	/usr/lib/libobjc.A.dylib
0x90a56000 - 0x90acafff com.apple.framework.IOKit 1.4 (???)	/System/Library/Frameworks/
IOKit.framework/Versions/A/IOKit
0x90ae4000 - 0x90af6fff libauto.dylib 	/usr/lib/libauto.dylib
0x90afd000 - 0x90dc2fff com.apple.CoreServices.CarbonCore 10.4.1 (611.1)
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
CarbonCore.framework/Versions/A/CarbonCore
0x90e25000 - 0x90ea5fff com.apple.CoreServices.OSServices 4.0 (4.0.0)
	/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/
OSServices.framework/Versions/A/OSServices
0x90eef000 - 0x90f2ffff com.apple.CFNetwork 10.4.2 (80)	/System/Library/Frameworks/
CoreServices.framework/Versions/A/Frameworks/CFNetwork.framework/Versions/A/CFNetwork
0x90f44000 - 0x90f5cfff com.apple.WebServices 1.1.2 (1.1.0)	/System/Library/Frameworks/
CoreServices.framework/Versions/A/Frameworks/WebServicesCore.framework/Versions/A/
WebServicesCore
0x90f6c000 - 0x90feafff com.apple.SearchKit 1.0.3	/System/Library/Frameworks/
CoreServices.framework/Versions/A/Frameworks/SearchKit.framework/Versions/A/SearchKit
0x9102f000 - 0x91056fff com.apple.Metadata 1.1 (121.6)	/System/Library/Frameworks/
CoreServices.framework/Versions/A/Frameworks/Metadata.framework/Versions/A/Metadata
0x91066000 - 0x91073fff libz.1.dylib 	/usr/lib/libz.1.dylib
0x91076000 - 0x91238fff com.apple.security 4.0.1 (223)	/System/Library/Frameworks/
Security.framework/Versions/A/Security
0x9133a000 - 0x91343fff com.apple.DiskArbitration 2.1	/System/Library/Frameworks/
DiskArbitration.framework/Versions/A/DiskArbitration
0x9134a000 - 0x91371fff com.apple.SystemConfiguration 1.8.0
	/System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfiguration
0x91384000 - 0x9138cfff libbsm.dylib 	/usr/lib/libbsm.dylib
0x91390000 - 0x9140efff com.apple.audio.CoreAudio 3.0.1	/System/Library/Frameworks/
CoreAudio.framework/Versions/A/CoreAudio
0x9144c000 - 0x9144cfff com.apple.ApplicationServices 10.4 (???)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/ApplicationServices
0x9144e000 - 0x91486fff com.apple.AE 1.5 (297)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/AE.framework/Versions/A/AE
0x914a1000 - 0x9156cfff com.apple.ColorSync 4.4	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/ColorSync.framework/Versions/A/ColorSync
0x915c1000 - 0x91654fff com.apple.print.framework.PrintCore 4.0 (172.1)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
PrintCore.framework/Versions/A/PrintCore
0x9169a000 - 0x91757fff com.apple.QD 3.8.6 (???)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/QD.framework/Versions/A/QD
0x91795000 - 0x917f3fff com.apple.HIServices 1.5.0 (???)	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/HIServices.framework/Versions/A/HIServices
0x91821000 - 0x91844fff com.apple.LangAnalysis 1.6	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/LangAnalysis.framework/Versions/A/
LangAnalysis
0x91858000 - 0x9187dfff com.apple.FindByContent 1.5	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/FindByContent.framework/Versions/A/
FindByContent
0x91890000 - 0x918d1fff com.apple.LaunchServices 10.4.3 (157)
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
LaunchServices.framework/Versions/A/LaunchServices
0x918ec000 - 0x91900fff com.apple.speech.synthesis.framework 3.3
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
SpeechSynthesis.framework/Versions/A/SpeechSynthesis
0x9190e000 - 0x91944fff com.apple.ImageIO.framework 1.0.2
	/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/
ImageIO.framework/Versions/A/ImageIO
0x91958000 - 0x91a1afff libcrypto.0.9.7.dylib 	/usr/lib/libcrypto.0.9.7.dylib
0x91a66000 - 0x91a7bfff libcups.2.dylib 	/usr/lib/libcups.2.dylib
0x91a80000 - 0x91a9cfff libJPEG.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libJPEG.dylib
0x91aa1000 - 0x91b10fff libJP2.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libJP2.dylib
0x91b27000 - 0x91b2bfff libGIF.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libGIF.dylib
0x91b2d000 - 0x91b45fff libRaw.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libRaw.dylib
0x91b48000 - 0x91b8bfff libTIFF.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libTIFF.dylib
0x91b92000 - 0x91babfff libPng.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libPng.dylib
0x91bb0000 - 0x91bb3fff libRadiance.dylib 	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/
libRadiance.dylib
0x91bb5000 - 0x91bb5fff com.apple.Accelerate 1.1.1 (Accelerate 1.1.1)
	/System/Library/Frameworks/Accelerate.framework/Versions/A/Accelerate
0x91bb7000 - 0x91ca1fff com.apple.vImage 2.0	/System/Library/Frameworks/
Accelerate.framework/Versions/A/Frameworks/vImage.framework/Versions/A/vImage
0x91ca9000 - 0x91cc8fff com.apple.Accelerate.vecLib 3.1.1 (vecLib 3.1.1)
	/System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/
Versions/A/vecLib
0x91d34000 - 0x91d54fff libmx.A.dylib 	/usr/lib/libmx.A.dylib
0x91d5a000 - 0x91dbffff libvMisc.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libvMisc.dylib
0x91dc9000 - 0x91e5bfff libvDSP.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libvDSP.dylib
0x91e75000 - 0x92405fff libBLAS.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libBLAS.dylib
0x9244d000 - 0x9275dfff libLAPACK.dylib 	/System/Library/Frameworks/Accelerate.framework/
Versions/A/Frameworks/vecLib.framework/Versions/A/libLAPACK.dylib
0x9278a000 - 0x92815fff com.apple.DesktopServices 1.3	/System/Library/PrivateFrameworks/
DesktopServicesPriv.framework/Versions/A/DesktopServicesPriv
0x92857000 - 0x92a80fff com.apple.Foundation 6.4.1 (567.12)
	/System/Library/Frameworks/Foundation.framework/Versions/C/Foundation
0x92b9e000 - 0x92c7cfff libxml2.2.dylib 	/usr/lib/libxml2.2.dylib
0x92c9c000 - 0x92d8afff libiconv.2.dylib 	/usr/lib/libiconv.2.dylib
0x92d9c000 - 0x92dbafff libGL.dylib 	/System/Library/Frameworks/OpenGL.framework/Versions/
A/Libraries/libGL.dylib
0x92dc5000 - 0x92e1ffff libGLU.dylib 	/System/Library/Frameworks/OpenGL.framework/Versions/
A/Libraries/libGLU.dylib
0x92e3d000 - 0x92e3dfff com.apple.Carbon 10.4 (???)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Carbon
0x92e3f000 - 0x92e53fff com.apple.ImageCapture 3.0	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/ImageCapture.framework/Versions/A/ImageCapture
0x92e6b000 - 0x92e7bfff com.apple.speech.recognition.framework 3.4
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
SpeechRecognition.framework/Versions/A/SpeechRecognition
0x92e87000 - 0x92e9cfff com.apple.securityhi 2.0 (203)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/SecurityHI.framework/Versions/A/SecurityHI
0x92eae000 - 0x92f35fff com.apple.ink.framework 101.2 (69)
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Ink.framework/
Versions/A/Ink
0x92f49000 - 0x92f54fff com.apple.help 1.0.3 (32)	/System/Library/Frameworks/Carbon.framework/
Versions/A/Frameworks/Help.framework/Versions/A/Help
0x92f5e000 - 0x92f8bfff com.apple.openscripting 1.2.2 (???)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/OpenScripting.framework/Versions/A/OpenScripting
0x92fa5000 - 0x92fb5fff com.apple.print.framework.Print 4.0 (187)
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Print.framework/
Versions/A/Print
0x92fc1000 - 0x93027fff com.apple.htmlrendering 1.1.2	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/HTMLRendering.framework/Versions/A/HTMLRendering
0x93058000 - 0x930aafff com.apple.NavigationServices 3.4.1 (3.4)
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
NavigationServices.framework/Versions/A/NavigationServices
0x930d6000 - 0x930f3fff com.apple.audio.SoundManager 3.9	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/CarbonSound.framework/Versions/A/CarbonSound
0x93105000 - 0x93112fff com.apple.CommonPanels 1.2.2 (73)
	/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/
CommonPanels.framework/Versions/A/CommonPanels
0x9311b000 - 0x9342bfff com.apple.HIToolbox 1.4.2 (???)	/System/Library/Frameworks/
Carbon.framework/Versions/A/Frameworks/HIToolbox.framework/Versions/A/HIToolbox
0x93576000 - 0x93582fff com.apple.opengl 1.4.0	/System/Library/Frameworks/OpenGL.framework/
Versions/A/OpenGL
0x93587000 - 0x935a9fff com.apple.DirectoryService.Framework 2.0
	/System/Library/Frameworks/DirectoryService.framework/Versions/A/DirectoryService
0x93615000 - 0x9361dfff libgcc_s.1.dylib 	/usr/lib/libgcc_s.1.dylib
0x93622000 - 0x93622fff com.apple.Cocoa 6.4 (???)	/System/Library/Frameworks/
Cocoa.framework/Versions/A/Cocoa
0x93624000 - 0x93c55fff com.apple.AppKit 6.4.1 (824.1)	/System/Library/Frameworks/
AppKit.framework/Versions/C/AppKit
0x93fe1000 - 0x9404bfff com.apple.CoreData 1.0 (46)	/System/Library/Frameworks/
CoreData.framework/Versions/A/CoreData
0x94083000 - 0x9414dfff com.apple.audio.toolbox.AudioToolbox 1.4.1
	/System/Library/Frameworks/AudioToolbox.framework/Versions/A/AudioToolbox
0x941a1000 - 0x941a1fff com.apple.audio.units.AudioUnit 1.4
	/System/Library/Frameworks/AudioUnit.framework/Versions/A/AudioUnit
0x941a3000 - 0x94302fff com.apple.QuartzCore 1.4.1	/System/Library/Frameworks/
QuartzCore.framework/Versions/A/QuartzCore
0x9434a000 - 0x94387fff libsqlite3.0.dylib 	/usr/lib/libsqlite3.0.dylib
0x9438f000 - 0x943dafff libGLImage.dylib 	/System/Library/Frameworks/OpenGL.framework/
Versions/A/Libraries/libGLImage.dylib
0x94468000 - 0x944a0fff com.apple.vmutils 4.0.0 (85)	/System/Library/PrivateFrameworks/
vmutils.framework/Versions/A/vmutils
0x944e3000 - 0x944fffff com.apple.securityfoundation 2.0 (262)
	/System/Library/Frameworks/SecurityFoundation.framework/Versions/A/SecurityFoundation
0x94513000 - 0x94556fff com.apple.securityinterface 2.0 (256)
	/System/Library/Frameworks/SecurityInterface.framework/Versions/A/SecurityInterface
0x9457a000 - 0x94589fff libCGATS.A.dylib 	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/
Resources/libCGATS.A.dylib
0x94591000 - 0x9459dfff libCSync.A.dylib 	/System/Library/Frameworks/
ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/
Resources/libCSync.A.dylib
0x945e2000 - 0x945f6fff libRIP.A.dylib 	/System/Library/Frameworks/ApplicationServices.framework/
Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libRIP.A.dylib
0x945fc000 - 0x9485efff com.apple.QuickTime 7.0.1	/System/Library/Frameworks/
QuickTime.framework/Versions/A/QuickTime
0x94931000 - 0x94950fff com.apple.vecLib 3.1.1 (vecLib 3.1.1)
	/System/Library/Frameworks/vecLib.framework/Versions/A/vecLib
0x94abe000 - 0x94bebfff com.apple.AddressBook.framework 4.0.2 (475)
	/System/Library/Frameworks/AddressBook.framework/Versions/A/AddressBook
0x94c7c000 - 0x94c8bfff com.apple.DSObjCWrappers.Framework 1.1
	/System/Library/PrivateFrameworks/DSObjCWrappers.framework/Versions/A/DSObjCWrappers
0x94c93000 - 0x94cbafff com.apple.LDAPFramework 1.4 (68)	/System/Library/Frameworks/
LDAP.framework/Versions/A/LDAP
0x94cc0000 - 0x94cd0fff libsasl2.2.dylib 	/usr/lib/libsasl2.2.dylib
0x94cd4000 - 0x94d02fff libssl.0.9.7.dylib 	/usr/lib/libssl.0.9.7.dylib
0x94d12000 - 0x94d2ffff libresolv.9.dylib 	/usr/lib/libresolv.9.dylib
0x95493000 - 0x95516fff libstdc++.6.dylib 	/usr/lib/libstdc++.6.dylib
0x9603e000 - 0x96067fff libxslt.1.dylib 	/usr/lib/libxslt.1.dylib
0x97ae0000 - 0x97aedfff com.apple.agl 2.5.6 (AGL-2.5.6)	/System/Library/Frameworks/
AGL.framework/Versions/A/AGL
0x9953e000 - 0x99cd0fff com.apple.QuickTimeComponents.component 7.0.1
	/System/Library/QuickTime/QuickTimeComponents.component/Contents/MacOS/
QuickTimeComponents
0x9b029000 - 0x9b05cfff com.apple.Syndication 1.0.1 (38)	/System/Library/PrivateFrameworks/
Syndication.framework/Versions/A/Syndication
0x9b077000 - 0x9b087fff com.apple.SyndicationUI 1.0.1 (38)	/System/Library/PrivateFrameworks/
SyndicationUI.framework/Versions/A/SyndicationUI
Comment 1 Kevin Broderick 2005-08-04 11:53:06 PDT
Created attachment 3226 [details]
Reduction

This two-line Javascript, when included, will crash ToT webkit.
Comment 2 Mark Rowe (bdash) 2005-08-06 22:56:53 PDT
Confirmed as a regression from system WebKit with ToT.
Comment 3 Mark Rowe (bdash) 2005-08-06 22:58:41 PDT
Created attachment 3252 [details]
Reduction wrapped in HTML for easy testing
Comment 4 Daniel Udey 2005-11-11 10:46:51 PST
This bug is no longer reproducible in 416.11 or ToT, and was most likely fixed in a previous update.