Reproduction steps 1. Go to https://trac.webkit.org/export/162218/trunk/PerformanceTests/DoYouEvenBench/InteractiveRunner.html 2. Uncheck "VanillaJS-TodoMVC" 3. Click "Run". Crash
<rdar://problem/16151521>
Is there a symbolicated crash log somewhere to look at?
This still reproduces with JSC_alwaysDoFullCollection=1 which implies it's not caused by the premature deallocation of a live object.
(In reply to comment #3) > This still reproduces with JSC_alwaysDoFullCollection=1 which implies it's not caused by the premature deallocation of a live object. I should say, it's not a premature deallocation of a live object due to generational collection. We could still be blowing away a live object during a full collection.
Throwing back to Ryosuke to verify that this has been fixed.
No longer seeing the crash.