This happens inside ::detach(). We may step over the end of the program and execution leads the VM to exit. Then, a GC happens, we collect the global object which leads us to detach the debugger. In detaching, we think we still have a valid m_currentCallFrame, we dereference it, and crash. The solution is to make sure we're paused when dereferencing this pointer inside ::detach().
Created attachment 276026 [details] patch
Comment on attachment 276026 [details] patch r=me. Would be better if you have a test. Or at least document why it's not possible to test. Or file a bug to land a test later.
(In reply to comment #2) > Comment on attachment 276026 [details] > patch > > r=me. > > Would be better if you have a test. Or at least document why it's not > possible to test. Or file a bug to land a test later. Thanks for the review. I opened a bug to investigate if it's doable to write a test. https://bugs.webkit.org/show_bug.cgi?id=156417
Comment on attachment 276026 [details] patch Clearing flags on attachment: 276026 Committed r199249: <http://trac.webkit.org/changeset/199249>
All reviewed patches have been landed. Closing bug.