For 32 bit builds, the helper maxOffsetRelativeToPatchedStorage() in JSObject.h should only add the "tag" offset for positive offset.
Created attachment 190169 [details] Patch
Committed r143994: <http://trac.webkit.org/changeset/143994>