WebKit nightly r38654 crashes on the above web page.
I can confirm this with a local debug build of r38680.
I thought this might be a reparsing bug, but it works fine in r38635, the revision that introduced reparsing.
I can verify that this regresses in r38652, the introduction of polymorphic caching of prototype accesses.
Created attachment 25373 [details] Ooops
Comment on attachment 25373 [details] Ooops Add a reference to this bug in the ChangeLog, and add a reproducibly failing layout test for this situation to fast/js/pic. Assuming you do that, r=me.
*** Bug 22408 has been marked as a duplicate of this bug. ***
Gavin, hopefully you can get around to making a test and landing this soon. This bug makes WebKit unusable for a lot of people.
Sending JavaScriptCore/ChangeLog Sending JavaScriptCore/jit/JIT.cpp Transmitting file data .. Committed revision 38697.
*** Bug 22438 has been marked as a duplicate of this bug. ***
*** Bug 22442 has been marked as a duplicate of this bug. ***
*** Bug 22445 has been marked as a duplicate of this bug. ***
*** Bug 22437 has been marked as a duplicate of this bug. ***
*** Bug 22446 has been marked as a duplicate of this bug. ***
*** Bug 22436 has been marked as a duplicate of this bug. ***
*** Bug 22435 has been marked as a duplicate of this bug. ***
(In reply to comment #8) > Sending JavaScriptCore/ChangeLog > Sending JavaScriptCore/jit/JIT.cpp Can a test be added for this bug?
*** Bug 22434 has been marked as a duplicate of this bug. ***
*** Bug 22424 has been marked as a duplicate of this bug. ***
*** Bug 22425 has been marked as a duplicate of this bug. ***
*** Bug 22422 has been marked as a duplicate of this bug. ***
*** Bug 22427 has been marked as a duplicate of this bug. ***