Created attachment 115305 [details] Patch to fix the crash by excluding the guard page from the stack. There is a 4kb guard page on the stack on QNX. The current code doesn't take this into account, causing it to crash before hitting the recursion/stack guard in WTF. Crashes multiple layout tests including large-expressions.js and regress-96526-002.js
Comment on attachment 115305 [details] Patch to fix the crash by excluding the guard page from the stack. Missing changelog
Created attachment 115314 [details] Add patch with changelog
Comment on attachment 115314 [details] Add patch with changelog View in context: https://bugs.webkit.org/attachment.cgi?id=115314&action=review Thanks for the patch! > Source/JavaScriptCore/wtf/StackBounds.cpp:110 > + m_bound = static_cast<char*>(stackBase) + 0x1000; // 4kb guard page This is OK as-is. We should look to query the OS for the page size.
Comment on attachment 115314 [details] Add patch with changelog Clearing flags on attachment: 115314 Committed r100406: <http://trac.webkit.org/changeset/100406>
All reviewed patches have been landed. Closing bug.
(In reply to comment #3) > (From update of attachment 115314 [details]) > View in context: https://bugs.webkit.org/attachment.cgi?id=115314&action=review > > Thanks for the patch! > > > Source/JavaScriptCore/wtf/StackBounds.cpp:110 > > + m_bound = static_cast<char*>(stackBase) + 0x1000; // 4kb guard page > > This is OK as-is. We should look to query the OS for the page size. There is no way to do that yet other than read the book, as far as I know.