There's a reproducible crash (assertion failure on debug is attempt to cast an immediate to a cell) when trying to step into a function call in a return statement. Steps to reproduce: 1. goto http://nerget.com/working/crash.html 2. Enable debugging 3. Set a breakpoint at the return statement in the code <script> function x(y){} window.onload = function () { return x(12); // <-- set break point here } </script> 4. Reload the page 5. When you reach the break point, step into the call 6. Crash :-(
I'll take a look at this.
This happens with the bytecode interpreter as well as the JIT, which should make it easier to debug.
Created attachment 25940 [details] Proposed patch
Comment on attachment 25940 [details] Proposed patch r=me!!!!!
Landed in r39198.