1. JSStack::disableErrorStackReserve() was wrongly comparing m_end with m_useableTop. Fixed the comparison. 2. JSStack::installTrapsAfterFrame() is wrongly overwriting the top slow of the top frame. Fixed to start the traps at the slot below (as in at lower memory than) the top slot in the top frame.
Created attachment 219941 [details] the patch.
Landed in r161038 on the jsCStack branch: <http://trac.webkit.org/r161038>.
Comment on attachment 219941 [details] the patch. Is it possible to have tests for this?
Both JSStack::disableErrorStackReserve() and JSStack::installTrapsAfterFrame() were removed in r161927: <http://trac.webkit.org/r161927> for https://bugs.webkit.org/show_bug.cgi?id=126790. This bug is no longer relevant. *** This bug has been marked as a duplicate of bug 126790 ***
Comment on attachment 219941 [details] the patch. Cleared review? from attachment 219941 [details] so that this bug does not appear in http://webkit.org/pending-review. If you would like this patch reviewed, please attach it to a new bug (or re-open this bug before marking it for review again).