The sentinel frame added in r158586 sets the return PC in the sentinel frame to 0. The sentinel frame is effectively the call frame for callToJavaScript and therefore should have the return PC set to its caller.
Created attachment 217063 [details] Patch
Committed r159346: <http://trac.webkit.org/changeset/159346>