As reported from http://code.google.com/p/chromium/issues/detail?id=71759:
Test case url : https://bug-40451-attachments.webkit.org/attachment.cgi?id=58498
What steps will reproduce the problem?
1. Go to that test case URL
2. Press the navigate button inside the iframe
3. Press the browser back button
4. Press the browser forward button
The navigation fails because the parent frame never commits its HistoryController's provisional item after step 3. (It currently crashes on step 4 because of a related memory error that is being fixed in bug 52819.)
Navigations in subframes set provisional items in their parent frames (as of http://trac.webkit.org/changeset/75336). We need to commit these provisional items in the frame tree during updateForSameDocumentNavigation, similar to updateForCommit.
I ended up including the fix for this as part of attachment 81286 [details] for bug 52819. Committed in r77705: