The layout test fast/js/exec-state-marking crashes in a few places, depending on how it is run, but it seems to be caused by incorrect garbage collection. There are similar issues using the web inspector on many pages.
Created attachment 20828 [details] Stack trace Here is a stack trace from gdb for fast/js/exec-state-marking. I made it GC every allocation.
This test no longer crashes.