Bug 19862 - REGRESSION (r34907): Gmail crashes in JavaScriptCore code while editing drafts
Summary: REGRESSION (r34907): Gmail crashes in JavaScriptCore code while editing drafts
Status: RESOLVED FIXED
Alias: None
Product: WebKit
Classification: Unclassified
Component: JavaScriptCore (show other bugs)
Version: 528+ (Nightly build)
Hardware: Mac OS X 10.5
: P1 Critical
Assignee: Nobody
URL: http://gmail.com
Keywords:
: 19845 (view as bug list)
Depends on:
Blocks:
 
Reported: 2008-07-02 17:12 PDT by Mike
Modified: 2008-07-02 23:48 PDT (History)
2 users (show)

See Also:


Attachments
GDB session (12.62 KB, text/plain)
2008-07-02 17:49 PDT, Cameron Zwarich (cpst)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Mike 2008-07-02 17:12:50 PDT
I don't know what the problem is but when working with a draft and saving it in gmail, I keep getting KJS error messages. Below is a sample error:


Process:         Safari [470]
Path:            /Applications/WebKit.app/Contents/MacOS/WebKit
Identifier:      org.webkit.nightly.WebKit
Version:         r34944 (34944)
Code Type:       X86 (Native)
Parent Process:  launchd [219]

Date/Time:       2008-07-02 20:10:31.224 -0400
OS Version:      Mac OS X 10.5.4 (9E17)
Report Version:  6

Exception Type:  EXC_BAD_ACCESS (SIGBUS)
Exception Codes: KERN_PROTECTION_FAILURE at 0x0000000000000060
Crashed Thread:  0

Thread 0 Crashed:
0   com.apple.JavaScriptCore      	0x003bc74d KJS::resolveBaseAndFunc(KJS::ExecState*, KJS::Instruction*, KJS::Register*, KJS::ScopeChainNode*, KJS::CodeBlock*, KJS::JSValue*&) + 109
1   com.apple.JavaScriptCore      	0x003bdfd7 KJS::Machine::privateExecute(KJS::Machine::ExecutionFlag, KJS::ExecState*, KJS::RegisterFile*, KJS::Register*, KJS::ScopeChainNode*, KJS::CodeBlock*, KJS::JSValue**) + 3767
2   com.apple.JavaScriptCore      	0x003c5cba KJS::Machine::execute(KJS::FunctionBodyNode*, KJS::ExecState*, KJS::JSFunction*, KJS::JSObject*, KJS::ArgList const&, KJS::ScopeChainNode*, KJS::JSValue**) + 682
3   com.apple.JavaScriptCore      	0x0036f045 KJS::JSFunction::call(KJS::ExecState*, KJS::JSValue*, KJS::ArgList const&) + 101
4   com.apple.JavaScriptCore      	0x0037021c KJS::functionProtoFuncCall(KJS::ExecState*, KJS::JSObject*, KJS::JSValue*, KJS::ArgList const&) + 252
5   com.apple.JavaScriptCore      	0x003c2799 KJS::Machine::privateExecute(KJS::Machine::ExecutionFlag, KJS::ExecState*, KJS::RegisterFile*, KJS::Register*, KJS::ScopeChainNode*, KJS::CodeBlock*, KJS::JSValue**) + 22137
6   com.apple.JavaScriptCore      	0x003c5cba KJS::Machine::execute(KJS::FunctionBodyNode*, KJS::ExecState*, KJS::JSFunction*, KJS::JSObject*, KJS::ArgList const&, KJS::ScopeChainNode*, KJS::JSValue**) + 682
7   com.apple.JavaScriptCore      	0x0036f045 KJS::JSFunction::call(KJS::ExecState*, KJS::JSValue*, KJS::ArgList const&) + 101
8   com.apple.JavaScriptCore      	0x0036faf0 KJS::functionProtoFuncApply(KJS::ExecState*, KJS::JSObject*, KJS::JSValue*, KJS::ArgList const&) + 560
9   com.apple.JavaScriptCore      	0x003c2799 KJS::Machine::privateExecute(KJS::Machine::ExecutionFlag, KJS::ExecState*, KJS::RegisterFile*, KJS::Register*, KJS::ScopeChainNode*, KJS::CodeBlock*, KJS::JSValue**) + 22137
10  com.apple.JavaScriptCore      	0x003c5cba KJS::Machine::execute(KJS::FunctionBodyNode*, KJS::ExecState*, KJS::JSFunction*, KJS::JSObject*, KJS::ArgList const&, KJS::ScopeChainNode*, KJS::JSValue**) + 682
11  com.apple.JavaScriptCore      	0x0036f045 KJS::JSFunction::call(KJS::ExecState*, KJS::JSValue*, KJS::ArgList const&) + 101
12  com.apple.JavaScriptCore      	0x0037021c KJS::functionProtoFuncCall(KJS::ExecState*, KJS::JSObject*, KJS::JSValue*, KJS::ArgList const&) + 252
13  com.apple.JavaScriptCore      	0x003c2799 KJS::Machine::privateExecute(KJS::Machine::ExecutionFlag, KJS::ExecState*, KJS::RegisterFile*, KJS::Register*, KJS::ScopeChainNode*, KJS::CodeBlock*, KJS::JSValue**) + 22137
14  com.apple.JavaScriptCore      	0x003c5cba KJS::Machine::execute(KJS::FunctionBodyNode*, KJS::ExecState*, KJS::JSFunction*, KJS::JSObject*, KJS::ArgList const&, KJS::ScopeChainNode*, KJS::JSValue**) + 682
15  com.apple.JavaScriptCore      	0x0036f045 KJS::JSFunction::call(KJS::ExecState*, KJS::JSValue*, KJS::ArgList const&) + 101
16  com.apple.JavaScriptCore      	0x0036faf0 KJS::functionProtoFuncApply(KJS::ExecState*, KJS::JSObject*, KJS::JSValue*, KJS::ArgList const&) + 560
17  com.apple.JavaScriptCore      	0x003c2799 KJS::Machine::privateExecute(KJS::Machine::ExecutionFlag, KJS::ExecState*, KJS::RegisterFile*, KJS::Register*, KJS::ScopeChainNode*, KJS::CodeBlock*, KJS::JSValue**) + 22137
18  com.apple.JavaScriptCore      	0x003c5cba KJS::Machine::execute(KJS::FunctionBodyNode*, KJS::ExecState*, KJS::JSFunction*, KJS::JSObject*, KJS::ArgList const&, KJS::ScopeChainNode*, KJS::JSValue**) + 682
19  com.apple.JavaScriptCore      	0x0036f045 KJS::JSFunction::call(KJS::ExecState*, KJS::JSValue*, KJS::ArgList const&) + 101
20  com.apple.JavaScriptCore      	0x0037021c KJS::functionProtoFuncCall(KJS::ExecState*, KJS::JSObject*, KJS::JSValue*, KJS::ArgList const&) + 252
21  com.apple.JavaScriptCore      	0x003c2799 KJS::Machine::privateExecute(KJS::Machine::ExecutionFlag, KJS::ExecState*, KJS::RegisterFile*, KJS::Register*, KJS::ScopeChainNode*, KJS::CodeBlock*, KJS::JSValue**) + 22137
22  com.apple.JavaScriptCore      	0x003c5cba KJS::Machine::execute(KJS::FunctionBodyNode*, KJS::ExecState*, KJS::JSFunction*, KJS::JSObject*, KJS::ArgList const&, KJS::ScopeChainNode*, KJS::JSValue**) + 682
23  com.apple.JavaScriptCore      	0x0036f045 KJS::JSFunction::call(KJS::ExecState*, KJS::JSValue*, KJS::ArgList const&) + 101
24  com.apple.JavaScriptCore      	0x0036faf0 KJS::functionProtoFuncApply(KJS::ExecState*, KJS::JSObject*, KJS::JSValue*, KJS::ArgList const&) + 560
25  com.apple.JavaScriptCore      	0x003c2799 KJS::Machine::privateExecute(KJS::Machine::ExecutionFlag, KJS::ExecState*, KJS::RegisterFile*, KJS::Register*, KJS::ScopeChainNode*, KJS::CodeBlock*, KJS::JSValue**) + 22137
26  com.apple.JavaScriptCore      	0x003c5cba KJS::Machine::execute(KJS::FunctionBodyNode*, KJS::ExecState*, KJS::JSFunction*, KJS::JSObject*, KJS::ArgList const&, KJS::ScopeChainNode*, KJS::JSValue**) + 682
27  com.apple.JavaScriptCore      	0x0036f045 KJS::JSFunction::call(KJS::ExecState*, KJS::JSValue*, KJS::ArgList const&) + 101
28  com.apple.JavaScriptCore      	0x0036faf0 KJS::functionProtoFuncApply(KJS::ExecState*, KJS::JSObject*, KJS::JSValue*, KJS::ArgList const&) + 560
29  com.apple.JavaScriptCore      	0x003c2799 KJS::Machine::privateExecute(KJS::Machine::ExecutionFlag, KJS::ExecState*, KJS::RegisterFile*, KJS::Register*, KJS::ScopeChainNode*, KJS::CodeBlock*, KJS::JSValue**) + 22137
30  com.apple.JavaScriptCore      	0x003c5cba KJS::Machine::execute(KJS::FunctionBodyNode*, KJS::ExecState*, KJS::JSFunction*, KJS::JSObject*, KJS::ArgList const&, KJS::ScopeChainNode*, KJS::JSValue**) + 682
31  com.apple.JavaScriptCore      	0x0036f045 KJS::JSFunction::call(KJS::ExecState*, KJS::JSValue*, KJS::ArgList const&) + 101
32  com.apple.WebCore             	0x01112d07 WebCore::ScheduledAction::execute(WebCore::JSDOMWindowShell*) + 503
33  com.apple.WebCore             	0x011d5615 WebCore::JSDOMWindowBase::timerFired(WebCore::DOMWindowTimer*) + 293
34  com.apple.WebCore             	0x011d5718 WebCore::DOMWindowTimer::fired() + 40
35  com.apple.WebCore             	0x01141bc9 WebCore::TimerBase::fireTimers(double, WTF::Vector<WebCore::TimerBase*, 0ul> const&) + 137
36  com.apple.WebCore             	0x01141c92 WebCore::TimerBase::sharedTimerFired() + 162
37  com.apple.WebCore             	0x01127124 WebCore::timerFired(__CFRunLoopTimer*, void*) + 68
38  com.apple.CoreFoundation      	0x90707b45 CFRunLoopRunSpecific + 4469
39  com.apple.CoreFoundation      	0x90707cf8 CFRunLoopRunInMode + 88
40  com.apple.HIToolbox           	0x9022ada4 RunCurrentEventLoopInMode + 283
41  com.apple.HIToolbox           	0x9022abbd ReceiveNextEventCommon + 374
42  com.apple.HIToolbox           	0x9022aa31 BlockUntilNextEventMatchingListInMode + 106
43  com.apple.AppKit              	0x93330505 _DPSNextEvent + 657
44  com.apple.AppKit              	0x9332fdb8 -[NSApplication nextEventMatchingMask:untilDate:inMode:dequeue:] + 128
45  com.apple.Safari              	0x000086be 0x1000 + 30398
46  com.apple.AppKit              	0x93328df3 -[NSApplication run] + 795
47  com.apple.AppKit              	0x932f6030 NSApplicationMain + 574
48  com.apple.Safari              	0x000ba4d6 0x1000 + 758998

Thread 1:
0   libSystem.B.dylib             	0x916fe68e __semwait_signal + 10
1   libSystem.B.dylib             	0x9172936d pthread_cond_wait$UNIX2003 + 73
2   com.apple.WebCore             	0x00e285ef WebCore::IconDatabase::syncThreadMainLoop() + 239
3   com.apple.WebCore             	0x00e28705 WebCore::IconDatabase::iconDatabaseSyncThread() + 181
4   libSystem.B.dylib             	0x917286f5 _pthread_start + 321
5   libSystem.B.dylib             	0x917285b2 thread_start + 34

Thread 2:
0   libSystem.B.dylib             	0x916f74a6 mach_msg_trap + 10
1   libSystem.B.dylib             	0x916fec9c mach_msg + 72
2   com.apple.CoreFoundation      	0x907070ce CFRunLoopRunSpecific + 1790
3   com.apple.CoreFoundation      	0x90707cf8 CFRunLoopRunInMode + 88
4   com.apple.CFNetwork           	0x90b2da32 CFURLCacheWorkerThread(void*) + 396
5   libSystem.B.dylib             	0x917286f5 _pthread_start + 321
6   libSystem.B.dylib             	0x917285b2 thread_start + 34

Thread 3:
0   libSystem.B.dylib             	0x916f74a6 mach_msg_trap + 10
1   libSystem.B.dylib             	0x916fec9c mach_msg + 72
2   com.apple.CoreFoundation      	0x907070ce CFRunLoopRunSpecific + 1790
3   com.apple.CoreFoundation      	0x90707cf8 CFRunLoopRunInMode + 88
4   com.apple.Foundation          	0x9594f460 +[NSURLConnection(NSURLConnectionReallyInternal) _resourceLoadLoop:] + 320
5   com.apple.Foundation          	0x958ebf1d -[NSThread main] + 45
6   com.apple.Foundation          	0x958ebac4 __NSThread__main__ + 308
7   libSystem.B.dylib             	0x917286f5 _pthread_start + 321
8   libSystem.B.dylib             	0x917285b2 thread_start + 34

Thread 4:
0   libSystem.B.dylib             	0x917475e2 select$DARWIN_EXTSN + 10
1   libSystem.B.dylib             	0x917286f5 _pthread_start + 321
2   libSystem.B.dylib             	0x917285b2 thread_start + 34

Thread 5:
0   libSystem.B.dylib             	0x916f74a6 mach_msg_trap + 10
1   libSystem.B.dylib             	0x916fec9c mach_msg + 72
2   ...romedia.Flash Player.plugin	0x134da959 memcopy_mmx + 709497
3   libSystem.B.dylib             	0x917286f5 _pthread_start + 321
4   libSystem.B.dylib             	0x917285b2 thread_start + 34

Thread 6:
0   libSystem.B.dylib             	0x916f74ee semaphore_wait_signal_trap + 10
1   libSystem.B.dylib             	0x91729866 _pthread_cond_wait + 1267
2   libSystem.B.dylib             	0x9176f371 pthread_cond_wait + 48
3   ...romedia.Flash Player.plugin	0x133a1928 0x1300f000 + 3746088
4   ...romedia.Flash Player.plugin	0x133d9230 Flash_EnforceLocalSecurity + 125000
5   ...romedia.Flash Player.plugin	0x133a1bd2 0x1300f000 + 3746770
6   libSystem.B.dylib             	0x917286f5 _pthread_start + 321
7   libSystem.B.dylib             	0x917285b2 thread_start + 34

Thread 7:
0   libSystem.B.dylib             	0x916f74ee semaphore_wait_signal_trap + 10
1   libSystem.B.dylib             	0x91729866 _pthread_cond_wait + 1267
2   libSystem.B.dylib             	0x9176f371 pthread_cond_wait + 48
3   ...romedia.Flash Player.plugin	0x133a1928 0x1300f000 + 3746088
4   ...romedia.Flash Player.plugin	0x133d9230 Flash_EnforceLocalSecurity + 125000
5   ...romedia.Flash Player.plugin	0x133a1bd2 0x1300f000 + 3746770
6   libSystem.B.dylib             	0x917286f5 _pthread_start + 321
7   libSystem.B.dylib             	0x917285b2 thread_start + 34

Thread 0 crashed with X86 Thread State (32-bit):
  eax: 0x00000000  ebx: 0x003bd131  ecx: 0x0aacb89c  edx: 0xbfff8f5c
  edi: 0x172bce60  esi: 0x125cf600  ebp: 0xbfff8428  esp: 0xbfff83e0
   ss: 0x0000001f  efl: 0x00010206  eip: 0x003bc74d   cs: 0x00000017
   ds: 0x0000001f   es: 0x0000001f   fs: 0x00000000   gs: 0x00000037
  cr2: 0x00000060

Binary Images:
    0x1000 -   0x133fef  com.apple.Safari 3.1.2 (5525.20.1) <b8911db3c9f4e89257f40775a27be7c6> /Applications/Safari.app/Contents/MacOS/Safari
  0x17b000 -   0x17cffc +WebKitNightlyEnabler.dylib ??? (???) /Applications/WebKit.app/Contents/Resources/WebKitNightlyEnabler.dylib
  0x181000 -   0x249fef  com.apple.WebKit r34944 (527+) /Applications/WebKit.app/Contents/Frameworks/10.5/WebKit.framework/Versions/A/WebKit
  0x2de000 -   0x2edff8  SyndicationUI ??? (???) <edde0133829971dbd8a0f3473cdb85fc> /System/Library/PrivateFrameworks/SyndicationUI.framework/Versions/A/SyndicationUI
  0x2fd000 -   0x3e7fef  com.apple.JavaScriptCore 527+ (527+) /Applications/WebKit.app/Contents/Frameworks/10.5/JavaScriptCore.framework/Versions/A/JavaScriptCore
  0x755000 -   0x75aff3  libCGXCoreImage.A.dylib ??? (???) <32265ec157db98a33c5dcf0e6687dec2> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libCGXCoreImage.A.dylib
  0xbfc000 -  0x1366fff  com.apple.WebCore 527+ (527+) /Applications/WebKit.app/Contents/Frameworks/10.5/WebCore.framework/Versions/A/WebCore
 0xb2cb000 -  0xb3e9ff7  com.apple.RawCamera.bundle 2.0.7 (2.0.7) /System/Library/CoreServices/RawCamera.bundle/Contents/MacOS/RawCamera
 0xe7c7000 -  0xe7c8ffc  com.apple.JavaPluginCocoa 12.1.0 (12.1.0) <d21a12c5668d4d89bfe492a5223a75cc> /Library/Internet Plug-Ins/JavaPluginCocoa.bundle/Contents/MacOS/JavaPluginCocoa
0x10d6c000 - 0x10d71ffd  com.apple.JavaVM 12.1.0 (12.1.0) <25c546c36e5bed978579d281080ab4c8> /System/Library/Frameworks/JavaVM.framework/Versions/A/JavaVM
0x11595000 - 0x11598fef  com.apple.LiveType.component 2.1.3 (2.1.3) /Library/QuickTime/LiveType.component/Contents/MacOS/LiveType
0x118e5000 - 0x118e802f +Motion ??? (???) <b5e862eee0ff4f86a78998e3e601a18c> /Library/Frameworks/Motion.framework/Versions/A/Motion
0x1300f000 - 0x1360fffb +com.macromedia.Flash Player.plugin 9.0.124 (1.0.4f60) <8355dcf076564b6784c517fd0eccb2f2> /Library/Internet Plug-Ins/Flash Player.plugin/Contents/MacOS/Flash Player
0x13750000 - 0x1376ffed  com.apple.audio.CoreAudioKit 1.5 (1.5) <82f2e52c502db7f3b32349a54209a0fe> /System/Library/Frameworks/CoreAudioKit.framework/Versions/A/CoreAudioKit
0x13820000 - 0x13885fde  com.apple.LiveType.framework 2.1.3 (2.1.3) /System/Library/PrivateFrameworks/LiveType.framework/Versions/A/LiveType
0x138a5000 - 0x138ebfc3  com.apple.motion.component 1.0 (1.0) <77973a134e79426f853f2318e52a2207> /Library/QuickTime/Motion.component/Contents/MacOS/Motion
0x8fe00000 - 0x8fe2da53  dyld 96.2 (???) <7af47d3b00b2268947563c7fa8c59a07> /usr/lib/dyld
0x90003000 - 0x900e8ff3  com.apple.CoreData 100.1 (186) <8e28162ef2288692615b52acc01f8b54> /System/Library/Frameworks/CoreData.framework/Versions/A/CoreData
0x901fb000 - 0x90502ff7  com.apple.HIToolbox 1.5.3 (???) <e36f5c553e5a32f64b7eb458dadadc71> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.framework/Versions/A/HIToolbox
0x90503000 - 0x905cefff  com.apple.ColorSync 4.5.0 (4.5.0) /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ColorSync.framework/Versions/A/ColorSync
0x905cf000 - 0x905d6fe9  libgcc_s.1.dylib ??? (???) <f53c808e87d1184c0f9df63aef53ce0b> /usr/lib/libgcc_s.1.dylib
0x905d7000 - 0x905dbfff  libmathCommon.A.dylib ??? (???) /usr/lib/system/libmathCommon.A.dylib
0x905dc000 - 0x90656ff8  com.apple.print.framework.PrintCore 5.5.3 (245.3) <222dade7b33b99708b8c09d1303f93fc> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/PrintCore.framework/Versions/A/PrintCore
0x90657000 - 0x9066dfe7  com.apple.CoreVideo 1.5.1 (1.5.1) <ed7bb95fb94817ea3212090aac5c65f3> /System/Library/Frameworks/CoreVideo.framework/Versions/A/CoreVideo
0x9066e000 - 0x90673fff  com.apple.CommonPanels 1.2.4 (85) <ea0665f57cd267609466ed8b2b20e893> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/CommonPanels.framework/Versions/A/CommonPanels
0x90674000 - 0x90674ffd  com.apple.Accelerate.vecLib 3.4.2 (vecLib 3.4.2) /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/vecLib
0x90675000 - 0x90694ffa  libJPEG.dylib ??? (???) <0cfb80109d624beb9ceb3c43b6c5ec10> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libJPEG.dylib
0x90695000 - 0x907c7fff  com.apple.CoreFoundation 6.5.3 (476.14) <7ef7f5db09ff6dd0135a6165872803cc> /System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
0x907c8000 - 0x907e0fff  com.apple.openscripting 1.2.6 (???) <b8e553df643f2aec68fa968b3b459b2b> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/OpenScripting.framework/Versions/A/OpenScripting
0x907e1000 - 0x90801ff2  libGL.dylib ??? (???) /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGL.dylib
0x90802000 - 0x9083bffe  com.apple.securityfoundation 3.0 (32989) <e9171eda22c69c884a04a001aeb526e0> /System/Library/Frameworks/SecurityFoundation.framework/Versions/A/SecurityFoundation
0x9083c000 - 0x9093dfef  com.apple.PubSub 1.0.3 (65.1.1) /System/Library/Frameworks/PubSub.framework/Versions/A/PubSub
0x9093e000 - 0x9093effd  com.apple.Accelerate 1.4.2 (Accelerate 1.4.2) /System/Library/Frameworks/Accelerate.framework/Versions/A/Accelerate
0x9094c000 - 0x90a2bfff  libobjc.A.dylib ??? (???) <a53206274b6c2d42691f677863f379ae> /usr/lib/libobjc.A.dylib
0x90a2c000 - 0x90ad3feb  com.apple.QD 3.11.52 (???) <c72bd7bd2ce12694c3640a731d1ad878> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/QD.framework/Versions/A/QD
0x90ad4000 - 0x90b15fe7  libRIP.A.dylib ??? (???) <c8d988d3880d7268468112c64c626d86> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libRIP.A.dylib
0x90b16000 - 0x90b21ff9  com.apple.helpdata 1.0 (14) /System/Library/PrivateFrameworks/HelpData.framework/Versions/A/HelpData
0x90b22000 - 0x90ba4ff3  com.apple.CFNetwork 330.4 (330.4) <ce5b085df34a78b7f198aff9db5b52ec> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/CFNetwork.framework/Versions/A/CFNetwork
0x90f0f000 - 0x90f9afff  com.apple.framework.IOKit 1.5.1 (???) <60cfc4b175c4ef60bb8e9036716a29f4> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
0x90f9b000 - 0x913abfef  libBLAS.dylib ??? (???) /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libBLAS.dylib
0x913ac000 - 0x91466fe3  com.apple.CoreServices.OSServices 226.5 (226.5) <7e10d25c615a39fe1ab4d48e24a3b555> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/OSServices.framework/Versions/A/OSServices
0x9159f000 - 0x916e5ff7  com.apple.ImageIO.framework 2.0.2 (2.0.2) <77dfee73f4c0d230425a5151ee0bce05> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/ImageIO
0x916e6000 - 0x916f5ffe  com.apple.DSObjCWrappers.Framework 1.2.1 (1.2.1) <eac1c7b7c07ed3148c85934b6f656308> /System/Library/PrivateFrameworks/DSObjCWrappers.framework/Versions/A/DSObjCWrappers
0x916f6000 - 0x91856ff3  libSystem.B.dylib ??? (???) <a12f397abf2285077b89bd726bff5b18> /usr/lib/libSystem.B.dylib
0x918a8000 - 0x918b2feb  com.apple.audio.SoundManager 3.9.2 (3.9.2) <0f2ba6e891d3761212cf5a5e6134d683> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/CarbonSound.framework/Versions/A/CarbonSound
0x91a6f000 - 0x91a6fffc  com.apple.audio.units.AudioUnit 1.5 (1.5) /System/Library/Frameworks/AudioUnit.framework/Versions/A/AudioUnit
0x91a70000 - 0x91c3efff  com.apple.security 5.0.4 (34102) <f01d6cbd6a0f24f6c13952ed448e77d6> /System/Library/Frameworks/Security.framework/Versions/A/Security
0x91c3f000 - 0x91c3fff8  com.apple.ApplicationServices 34 (34) <8f910fa65f01d401ad8d04cc933cf887> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/ApplicationServices
0x91c40000 - 0x91c64feb  libssl.0.9.7.dylib ??? (???) <acee7fc534674498dcac211318aa23e8> /usr/lib/libssl.0.9.7.dylib
0x91c65000 - 0x91c92feb  libvDSP.dylib ??? (???) <b232c018ddd040ec4e2c2af632dd497f> /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libvDSP.dylib
0x92f72000 - 0x92f79ffe  libbsm.dylib ??? (???) <d25c63378a5029648ffd4b4669be31bf> /usr/lib/libbsm.dylib
0x92f7a000 - 0x9300dff3  com.apple.ApplicationServices.ATS 3.3 (???) <064eb6d96417afa38a80b1735c4113aa> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ATS.framework/Versions/A/ATS
0x9300e000 - 0x9301dfff  libsasl2.2.dylib ??? (???) <b9e1ca0b6612e280b6cbea6df0eec5f6> /usr/lib/libsasl2.2.dylib
0x9301e000 - 0x9309dff5  com.apple.SearchKit 1.2.0 (1.2.0) <277b460da86bc222785159fe77e2e2ed> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/SearchKit.framework/Versions/A/SearchKit
0x930bc000 - 0x930e0fff  libxslt.1.dylib ??? (???) <4933ddc7f6618743197aadc85b33b5ab> /usr/lib/libxslt.1.dylib
0x930e1000 - 0x9313effb  libstdc++.6.dylib ??? (???) <04b812dcec670daa8b7d2852ab14be60> /usr/lib/libstdc++.6.dylib
0x9313f000 - 0x931cbff7  com.apple.LaunchServices 289.2 (289.2) <3577886e3a6d56ee3949850c4fde76c9> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/LaunchServices
0x931cc000 - 0x931ceff5  libRadiance.dylib ??? (???) <20eadb285da83df96c795c2c5fa20590> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libRadiance.dylib
0x931cf000 - 0x93209fff  com.apple.coreui 1.1 (61) /System/Library/PrivateFrameworks/CoreUI.framework/Versions/A/CoreUI
0x9320a000 - 0x9320dfff  com.apple.help 1.1 (36) <b507b08e484cb89033e9cf23062d77de> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Help.framework/Versions/A/Help
0x9320e000 - 0x932efff7  libxml2.2.dylib ??? (???) <1baef3d4972ee789d8fa6c1fa44da45c> /usr/lib/libxml2.2.dylib
0x932f0000 - 0x93aedfef  com.apple.AppKit 6.5.3 (949.33) <84b236f43802f4c15011513d18efa101> /System/Library/Frameworks/AppKit.framework/Versions/C/AppKit
0x93aee000 - 0x93aeeffb  com.apple.installserver.framework 1.0 (8) /System/Library/PrivateFrameworks/InstallServer.framework/Versions/A/InstallServer
0x93aef000 - 0x93c27ff7  libicucore.A.dylib ??? (???) <5031226ea28b371d8dfdbb32acfb48b5> /usr/lib/libicucore.A.dylib
0x93ccb000 - 0x93cd7fe7  com.apple.opengl 1.5.6 (1.5.6) <125de77ea2434a91364e79a0905a7771> /System/Library/Frameworks/OpenGL.framework/Versions/A/OpenGL
0x93cd8000 - 0x93cd8fff  com.apple.Carbon 136 (136) <98a5e3bc0c4fa44bbb09713bb88707fe> /System/Library/Frameworks/Carbon.framework/Versions/A/Carbon
0x93cd9000 - 0x93d63fe3  com.apple.DesktopServices 1.4.6 (1.4.6) <94d1a28b351b7dff77becadab0967772> /System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Versions/A/DesktopServicesPriv
0x93d64000 - 0x93d72ffd  libz.1.dylib ??? (???) <5ddd8539ae2ebfd8e7cc1c57525385c7> /usr/lib/libz.1.dylib
0x93d73000 - 0x93db5fef  com.apple.NavigationServices 3.5.2 (163) <91844980804067b07a0b6124310d3f31> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/NavigationServices.framework/Versions/A/NavigationServices
0x93e24000 - 0x941e2fea  libLAPACK.dylib ??? (???) /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libLAPACK.dylib
0x941e3000 - 0x941ebfff  com.apple.DiskArbitration 2.2.1 (2.2.1) <75b0c8d8940a8a27816961dddcac8e0f> /System/Library/Frameworks/DiskArbitration.framework/Versions/A/DiskArbitration
0x941ec000 - 0x941f3fff  com.apple.agl 3.0.9 (AGL-3.0.9) <7dac4a7cb0de2f6d08ae71c1249379e3> /System/Library/Frameworks/AGL.framework/Versions/A/AGL
0x9420d000 - 0x944e7ff3  com.apple.CoreServices.CarbonCore 786.4 (786.4) <059c4803a7a95e3c1a95a332baeb1edf> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/CarbonCore.framework/Versions/A/CarbonCore
0x944e8000 - 0x944fefff  com.apple.DictionaryServices 1.0.0 (1.0.0) <ad0aa0252e3323d182e17f50defe56fc> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/DictionaryServices.framework/Versions/A/DictionaryServices
0x944ff000 - 0x9455bff7  com.apple.htmlrendering 68 (1.1.3) <fe87a9dede38db00e6c8949942c6bd4f> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HTMLRendering.framework/Versions/A/HTMLRendering
0x9462c000 - 0x9494dfea  com.apple.QuickTime 7.5.0 (861) <4e1161b204b3b1f1047412c16483c39a> /System/Library/Frameworks/QuickTime.framework/Versions/A/QuickTime
0x9494e000 - 0x949cafeb  com.apple.audio.CoreAudio 3.1.0 (3.1) <70bb7c657061631491029a61babe0b26> /System/Library/Frameworks/CoreAudio.framework/Versions/A/CoreAudio
0x949cb000 - 0x94a24ff7  libGLU.dylib ??? (???) /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGLU.dylib
0x94a25000 - 0x94ab8fff  com.apple.ink.framework 101.3 (86) <bf3fa8927b4b8baae92381a976fd2079> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Ink.framework/Versions/A/Ink
0x94abf000 - 0x94c3efff  com.apple.AddressBook.framework 4.1.1 (695) <24a448ba4f9f784189bd3183e3474d81> /System/Library/Frameworks/AddressBook.framework/Versions/A/AddressBook
0x94c3f000 - 0x94c53ff3  com.apple.ImageCapture 4.0 (5.0.0) /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/ImageCapture.framework/Versions/A/ImageCapture
0x94c54000 - 0x94c72fff  libresolv.9.dylib ??? (???) <0629b6dcd71f4aac6a891cbe26253e85> /usr/lib/libresolv.9.dylib
0x94c73000 - 0x94ca9fef  libtidy.A.dylib ??? (???) <f1d1742e06280444baa5637b209fd0af> /usr/lib/libtidy.A.dylib
0x94cdf000 - 0x94ce3fff  libGIF.dylib ??? (???) <d4234e6f5e5f530bdafb969157f1f17b> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libGIF.dylib
0x94ce4000 - 0x94ce5ffc  libffi.dylib ??? (???) <a3b573eb950ca583290f7b2b4c486d09> /usr/lib/libffi.dylib
0x94d11000 - 0x94d43fff  com.apple.LDAPFramework 1.4.3 (106) <3a5c9df6032143cd6bc2658a9d328d8e> /System/Library/Frameworks/LDAP.framework/Versions/A/LDAP
0x94d93000 - 0x94daeff3  libPng.dylib ??? (???) <c0484bec6e2432b406755591924fe664> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libPng.dylib
0x94daf000 - 0x94db6ff7  libCGATS.A.dylib ??? (???) <9b29a5500efe01cc3adea67bbc42568e> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libCGATS.A.dylib
0x94db7000 - 0x94db7ffd  com.apple.vecLib 3.4.2 (vecLib 3.4.2) /System/Library/Frameworks/vecLib.framework/Versions/A/vecLib
0x94e3a000 - 0x951d0fff  com.apple.QuartzCore 1.5.3 (1.5.3) <1b65c05f89e81a499302fd63295b242d> /System/Library/Frameworks/QuartzCore.framework/Versions/A/QuartzCore
0x951d1000 - 0x9586dfff  com.apple.CoreGraphics 1.351.31 (???) <c97a42498636b2596764e48669f98e00> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/CoreGraphics
0x958e1000 - 0x95b5cfe7  com.apple.Foundation 6.5.5 (677.19) <bfd4ebea1a7739dd6b523f15dca01a37> /System/Library/Frameworks/Foundation.framework/Versions/C/Foundation
0x95b62000 - 0x95bb2ff7  com.apple.HIServices 1.7.0 (???) <f7e78891a6d08265c83dca8e378be1ea> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/HIServices.framework/Versions/A/HIServices
0x95bb3000 - 0x95bdbfff  libcups.2.dylib ??? (???) <ece20dff2a2c8ed3ae6ef735ef440c37> /usr/lib/libcups.2.dylib
0x95bdc000 - 0x95becffc  com.apple.LangAnalysis 1.6.4 (1.6.4) <8b7831b5f74a950a56cf2d22a2d436f6> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/LangAnalysis.framework/Versions/A/LangAnalysis
0x95bed000 - 0x95c18fe7  libauto.dylib ??? (???) <42d8422dc23a18071869fdf7b5d8fab5> /usr/lib/libauto.dylib
0x95c19000 - 0x95c19ff8  com.apple.Cocoa 6.5 (???) <e064f94d969ce25cb7de3cfb980c3249> /System/Library/Frameworks/Cocoa.framework/Versions/A/Cocoa
0x95c1a000 - 0x95c23fff  com.apple.speech.recognition.framework 3.7.24 (3.7.24) <d3180f9edbd9a5e6f283d6156aa3c602> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/SpeechRecognition.framework/Versions/A/SpeechRecognition
0x95c24000 - 0x95c7eff7  com.apple.CoreText 2.0.2 (???) <9fde11f84a72e890bbf2aa8b0b13b79a> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreText.framework/Versions/A/CoreText
0x95cbe000 - 0x95d70ffb  libcrypto.0.9.7.dylib ??? (???) <330b0e48e67faffc8c22dfc069ca7a47> /usr/lib/libcrypto.0.9.7.dylib
0x95d8a000 - 0x95e07fef  libvMisc.dylib ??? (???) /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.framework/Versions/A/libvMisc.dylib
0x95e08000 - 0x962dbffe  libGLProgrammability.dylib ??? (???) <475db64244e011cd8811e076035b2632> /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGLProgrammability.dylib
0x962dc000 - 0x962e1fff  com.apple.backup.framework 1.0 (1.0) /System/Library/PrivateFrameworks/Backup.framework/Versions/A/Backup
0x962e2000 - 0x96300ff3  com.apple.DirectoryService.Framework 3.5.4 (3.5.4) <fe27e80e1a9e86403fd9ed16dcfe4e11> /System/Library/Frameworks/DirectoryService.framework/Versions/A/DirectoryService
0x963d5000 - 0x96485fff  edu.mit.Kerberos 6.0.12 (6.0.12) <1dc515ebe407292db8e603938c72d4e8> /System/Library/Frameworks/Kerberos.framework/Versions/A/Kerberos
0x96486000 - 0x964aeff7  com.apple.shortcut 1 (1.0) <057783867138902b52bc0941fedb74d1> /System/Library/PrivateFrameworks/Shortcut.framework/Versions/A/Shortcut
0x964af000 - 0x964bffff  com.apple.speech.synthesis.framework 3.7.1 (3.7.1) <06d8fc0307314f8ffc16f206ad3dbf44> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/SpeechSynthesis.framework/Versions/A/SpeechSynthesis
0x964c0000 - 0x964fffef  libTIFF.dylib ??? (???) <6d0f80e9d4d81f3f64c876aca005bd53> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ImageIO.framework/Versions/A/Resources/libTIFF.dylib
0x96500000 - 0x96500ffa  com.apple.CoreServices 32 (32) <2fcc8f3bd5bbfc000b476cad8e6a3dd2> /System/Library/Frameworks/CoreServices.framework/Versions/A/CoreServices
0x96501000 - 0x9654bfe1  com.apple.securityinterface 3.0 (32532) <f521dae416ce7a3bdd594b0d4e2fb517> /System/Library/Frameworks/SecurityInterface.framework/Versions/A/SecurityInterface
0x9654c000 - 0x96670fe3  com.apple.audio.toolbox.AudioToolbox 1.5.1 (1.5.1) /System/Library/Frameworks/AudioToolbox.framework/Versions/A/AudioToolbox
0x96671000 - 0x9667cfe7  libCSync.A.dylib ??? (???) <8011fc1963cebdde0c6f101dbee5afd7> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/CoreGraphics.framework/Versions/A/Resources/libCSync.A.dylib
0x9667d000 - 0x966b4fff  com.apple.SystemConfiguration 1.9.2 (1.9.2) <8b26ebf26a009a098484f1ed01ec499c> /System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfiguration
0x966b5000 - 0x966fbfef  com.apple.Metadata 10.5.2 (398.18) <adbb3a14e8f7da444e16d2fd61862771> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/Metadata.framework/Versions/A/Metadata
0x967dd000 - 0x96864ff7  libsqlite3.0.dylib ??? (???) <6978bbcca4277d6ae9f042beff643f7d> /usr/lib/libsqlite3.0.dylib
0x96897000 - 0x96899fff  com.apple.securityhi 3.0 (30817) <2b2854123fed609d1820d2779e2e0963> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/SecurityHI.framework/Versions/A/SecurityHI
0x9689a000 - 0x968a0fff  com.apple.print.framework.Print 218.0.2 (220.1) <8bf7ef71216376d12fcd5ec17e43742c> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Print.framework/Versions/A/Print
0x96ae7000 - 0x96ae9fff  com.apple.CrashReporterSupport 10.5.0 (156) <3088b785b10d03504ed02f3fee5d3aab> /System/Library/PrivateFrameworks/CrashReporterSupport.framework/Versions/A/CrashReporterSupport
0x96aea000 - 0x96b28ff7  libGLImage.dylib ??? (???) <093b1b698ca93a0380f5fa262459ea28> /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGLImage.dylib
0x96b33000 - 0x96b99ffb  com.apple.ISSupport 1.7 (38) /System/Library/PrivateFrameworks/ISSupport.framework/Versions/A/ISSupport
0x96b9a000 - 0x96c61ff2  com.apple.vImage 3.0 (3.0) /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vImage.framework/Versions/A/vImage
0x972c1000 - 0x972f0fe3  com.apple.AE 402.2 (402.2) <e01596187e91af5d48653920017b8c8e> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/AE.framework/Versions/A/AE
0xfffe8000 - 0xfffebfff  libobjc.A.dylib ??? (???) /usr/lib/libobjc.A.dylib
0xffff0000 - 0xffff1780  libSystem.B.dylib ??? (???) /usr/lib/libSystem.B.dylib
Comment 1 Cameron Zwarich (cpst) 2008-07-02 17:26:45 PDT
Editing drafts in a release build gives me a crash with an essentially identical stack trace. I'll try to reproduce in gdb-safari.
Comment 2 Cameron Zwarich (cpst) 2008-07-02 17:49:46 PDT
Created attachment 22055 [details]
GDB session

It hits an assertion failure somewhere else, in the middle of the op_ret body.
Comment 3 Cameron Zwarich (cpst) 2008-07-02 17:51:17 PDT
It looks like the JSActivation was already collected, because its _vptr is 0.
Comment 4 Cameron Zwarich (cpst) 2008-07-02 18:11:05 PDT
I can't reproduce this in the r34824 nightly, but I can reproduce it fairly reliably with the r34941 nightly.
Comment 5 Cameron Zwarich (cpst) 2008-07-02 20:05:02 PDT
*** Bug 19845 has been marked as a duplicate of this bug. ***
Comment 6 Cameron Zwarich (cpst) 2008-07-02 20:14:31 PDT
This is not reproducible in r34837, and the time bug 19845 was reported implies it couldn't have been later than r34918.
Comment 7 Cameron Zwarich (cpst) 2008-07-02 21:31:30 PDT
I can reproduce this consistently with r34907. I couldn't reproduce it with r34906 before, but I now have a consistent way of reproducing it:

1) Open a blank draft.

2) Write about a line of text.

3) Copy it.

4) Hold down command-V and keep on pasting until it crashes.

I am recompiling r34906 to see if I have isolated it.
Comment 8 Cameron Zwarich (cpst) 2008-07-02 21:46:05 PDT
The crash is indeed caused by r34907, as expected.
Comment 9 Geoffrey Garen 2008-07-02 22:15:39 PDT
Looks like the register file didn't get marked, so the activation was collected. I suspect in this case the only reference to the global object was in the register file itself.
Comment 10 Geoffrey Garen 2008-07-02 23:48:15 PDT
Committed revision 34974.