Bug 22413 - REGRESSION (r38652): Google Code page crashes WebKit
: REGRESSION (r38652): Google Code page crashes WebKit
Status: RESOLVED FIXED
: WebKit
New Bugs
: 528+ (Nightly build)
: Macintosh Mac OS X 10.5
: P1 Normal
Assigned To:
: http://code.google.com/apis/ajaxlibs/...
: GoogleBug, NeedsReduction, Regression
:
:
  Show dependency treegraph
 
Reported: 2008-11-21 14:25 PST by
Modified: 2008-11-24 03:16 PST (History)


Attachments
Ooops (984 bytes, patch)
2008-11-22 01:15 PST, Gavin Barraclough
zwarich: review+
Review Patch | Details | Formatted Diff | Diff


Note

You need to log in before you can comment on or make changes to this bug.


Description From 2008-11-21 14:25:19 PST
WebKit nightly r38654 crashes on the above web page.
------- Comment #1 From 2008-11-21 21:41:51 PST -------
I can confirm this with a local debug build of r38680.
------- Comment #2 From 2008-11-21 22:40:49 PST -------
I thought this might be a reparsing bug, but it works fine in r38635, the revision that introduced reparsing.
------- Comment #3 From 2008-11-21 23:18:30 PST -------
I can verify that this regresses in r38652, the introduction of polymorphic caching of prototype accesses.
------- Comment #4 From 2008-11-22 01:15:56 PST -------
Created an attachment (id=25373) [details]
Ooops
------- Comment #5 From 2008-11-22 04:00:50 PST -------
(From update of attachment 25373 [details])
Add a reference to this bug in the ChangeLog, and add a reproducibly failing layout test for this situation to fast/js/pic. Assuming you do that, r=me.
------- Comment #6 From 2008-11-22 04:31:04 PST -------
*** Bug 22408 has been marked as a duplicate of this bug. ***
------- Comment #7 From 2008-11-23 21:31:31 PST -------
Gavin, hopefully you can get around to making a test and landing this soon. This bug makes WebKit unusable for a lot of people.
------- Comment #8 From 2008-11-23 22:01:50 PST -------
Sending        JavaScriptCore/ChangeLog
Sending        JavaScriptCore/jit/JIT.cpp
Transmitting file data ..
Committed revision 38697.
------- Comment #9 From 2008-11-24 00:33:53 PST -------
*** Bug 22438 has been marked as a duplicate of this bug. ***
------- Comment #10 From 2008-11-24 00:34:00 PST -------
*** Bug 22442 has been marked as a duplicate of this bug. ***
------- Comment #11 From 2008-11-24 00:34:09 PST -------
*** Bug 22445 has been marked as a duplicate of this bug. ***
------- Comment #12 From 2008-11-24 00:34:14 PST -------
*** Bug 22437 has been marked as a duplicate of this bug. ***
------- Comment #13 From 2008-11-24 00:34:21 PST -------
*** Bug 22446 has been marked as a duplicate of this bug. ***
------- Comment #14 From 2008-11-24 00:34:27 PST -------
*** Bug 22436 has been marked as a duplicate of this bug. ***
------- Comment #15 From 2008-11-24 00:34:37 PST -------
*** Bug 22435 has been marked as a duplicate of this bug. ***
------- Comment #16 From 2008-11-24 01:35:09 PST -------
(In reply to comment #8)
> Sending        JavaScriptCore/ChangeLog
> Sending        JavaScriptCore/jit/JIT.cpp

Can a test be added for this bug?
------- Comment #17 From 2008-11-24 03:15:31 PST -------
*** Bug 22434 has been marked as a duplicate of this bug. ***
------- Comment #18 From 2008-11-24 03:15:52 PST -------
*** Bug 22424 has been marked as a duplicate of this bug. ***
------- Comment #19 From 2008-11-24 03:16:01 PST -------
*** Bug 22425 has been marked as a duplicate of this bug. ***
------- Comment #20 From 2008-11-24 03:16:11 PST -------
*** Bug 22422 has been marked as a duplicate of this bug. ***
------- Comment #21 From 2008-11-24 03:16:25 PST -------
*** Bug 22427 has been marked as a duplicate of this bug. ***