SquirrelFish crashes on the site http://blog.wired.com/games/2008/05/for-wiiware-nin.html with the following assertion failure: ASSERTION FAILED: activation->isActivationObject() (/Users/Cameron/sf/JavaScriptCore/VM/Machine.cpp:523 bool KJS::Machine::unwindCallFrame(KJS::ExecState*, KJS::Register**, const KJS::Instruction*&, KJS::CodeBlock*&, KJS::JSValue**&, KJS::ScopeChainNode*&, KJS::Register*&)) I occasionally need to reload to get it to crash.
Created attachment 21096 [details] Reduction Here is a partial reduction of this bug. Even though the crash occurs in the SHARETHIS code, I needed to create and add the flash object earlier to get the crash to occur. It should be possible to further reduce the library code to get some idea of what is going on.
Created attachment 21098 [details] Further reduction Here is a further reduction, including the library source. When I tried to reduce it more, I sometimes got a plain crash instead of an assertion failure.
Created attachment 21100 [details] Further reduction Here's a further reduction of the bug. Most of the library code is irrelevant to the assertion failure. The assertion failure doesn't occur when I replace the eval at the beginning with an eval of the actual JS source produced.
Created attachment 21101 [details] Further reduction Here's a further reduction. This one doesn't trigger the same assertion. Instead, it hits this assertion: ASSERTION FAILED: isNumber(v) (/Users/Cameron/sf/JavaScriptCore/kjs/JSImmediate.cpp:44 static KJS::JSObject* KJS::JSImmediate::toObject(const KJS::JSValue*, KJS::ExecState*))
Comment on attachment 21101 [details] Further reduction This test is actually a test of bug #19025
Comment on attachment 21100 [details] Further reduction I was wrong
M JavaScriptCore/ChangeLog M JavaScriptCore/VM/Machine.cpp M JavaScriptCore/VM/RegisterFile.cpp M JavaScriptCore/VM/RegisterFileStack.cpp M JavaScriptCore/VM/RegisterFileStack.h M LayoutTests/ChangeLog A LayoutTests/fast/js/implicit-global-to-global-reentry-expected.txt A LayoutTests/fast/js/implicit-global-to-global-reentry.html Committed r33438