Occasionally when running new-run-webkit-tests we can get a failure when the garbage collector decides to do a collection in the middle of initializing a structure chain in Interpreter.cpp around line 1396. It's difficult to reproduce on its own due to the fact that it depends on what the garbage collector is doing up to that point of the test. An easy fix would be to move the allocation of the prototypeChain before calling getOpcode.
Created attachment 102850 [details] Patch
Comment on attachment 102850 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=102850&action=review > Source/JavaScriptCore/interpreter/Interpreter.cpp:1392 > + StructureChain* prototypeChain = structure->prototypeChain(callFrame); I think it make sense to document why you do the call here and use a local so that some future unsuspecting engineer doesn't reintroduce the bug by eliminating the local.
Created attachment 102859 [details] Patch
Comment on attachment 102859 [details] Patch Clearing flags on attachment: 102859 Committed r92393: <http://trac.webkit.org/changeset/92393>
All reviewed patches have been landed. Closing bug.