There is an arithmetic bug in dataTransfer32. If the offset of dataTransfer is half of the addressable memory space on a 32-bit machine (-2147483648 = 0x80000000) a load instruction is emitted with a wrong zero offset.
Created attachment 100257 [details] Signed arithmetic bug in dataTransfer32
Comment on attachment 100257 [details] Signed arithmetic bug in dataTransfer32 Nice catch.
Comment on attachment 100257 [details] Signed arithmetic bug in dataTransfer32 Clearing flags on attachment: 100257 Committed r90731: <http://trac.webkit.org/changeset/90731>
All reviewed patches have been landed. Closing bug.
Regression test?
(In reply to comment #5) > Regression test? Seemed impossible. 0x80000000 (INT_MIN) is too big offset on a 32 bit machine. This is a "theoretical" bug.