<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>163337</bug_id>
          
          <creation_ts>2016-10-12 09:53:36 -0700</creation_ts>
          <short_desc>REGRESSION (r207179): ASSERTION FAILED: node.cell != previousCell</short_desc>
          <delta_ts>2016-10-12 20:11:47 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>New Bugs</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>149432</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="Ryan Haddad">ryanhaddad</reporter>
          <assigned_to name="Filip Pizlo">fpizlo</assigned_to>
          <cc>commit-queue</cc>
    
    <cc>fpizlo</cc>
    
    <cc>keith_miller</cc>
    
    <cc>mark.lam</cc>
    
    <cc>msaboff</cc>
    
    <cc>saam</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1239334</commentid>
    <comment_count>0</comment_count>
    <who name="Ryan Haddad">ryanhaddad</who>
    <bug_when>2016-10-12 09:53:36 -0700</bug_when>
    <thetext>ASSERTION FAILED: node.cell != previousCell
/Volumes/Data/slave/elcapitan-debug/build/Source/JavaScriptCore/heap/HeapSnapshot.cpp(125) : void JSC::HeapSnapshot::finalize()
1   0x104083180 WTFCrash
2   0x103ec60b4 JSC::HeapSnapshot::finalize()
3   0x103a872cc JSC::HeapSnapshotBuilder::buildSnapshot()
4   0x10398fc06 Inspector::InspectorHeapAgent::snapshot(WTF::String&amp;, double*, WTF::String*)
5   0x1039623c2 Inspector::InspectorConsoleAgent::takeHeapSnapshot(WTF::String const&amp;)
6   0x10a22d25b WebCore::InspectorInstrumentation::takeHeapSnapshotImpl(WebCore::InstrumentingAgents&amp;, WTF::String const&amp;)
7   0x10afb3b15 WebCore::InspectorInstrumentation::takeHeapSnapshot(WebCore::Frame&amp;, WTF::String const&amp;)
8   0x10afb351d WebCore::PageConsoleClient::takeHeapSnapshot(JSC::ExecState*, WTF::String const&amp;)
9   0x1031217ce JSC::consoleProtoFuncTakeHeapSnapshot(JSC::ExecState*)
10  0x4c83c4e01028
11  0x103c5a054 llint_entry
12  0x103c5a054 llint_entry
13  0x103c52b6e vmEntryToJavaScript
14  0x103a3419c JSC::JITCode::execute(JSC::VM*, JSC::ProtoCallFrame*)
15  0x1039b04ae JSC::Interpreter::execute(JSC::ProgramExecutable*, JSC::ExecState*, JSC::JSObject*)
16  0x1032cc455 JSC::evaluate(JSC::ExecState*, JSC::SourceCode const&amp;, JSC::JSValue, WTF::NakedPtr&lt;JSC::Exception&gt;&amp;)
17  0x1032cc69e JSC::evaluateWithScopeExtension(JSC::ExecState*, JSC::SourceCode const&amp;, JSC::JSObject*, WTF::NakedPtr&lt;JSC::Exception&gt;&amp;)
18  0x103b2126b Inspector::JSInjectedScriptHost::evaluateWithScopeExtension(JSC::ExecState*)
19  0x103b2837a Inspector::jsInjectedScriptHostPrototypeFunctionEvaluateWithScopeExtension(JSC::ExecState*)
20  0x4c83c4e01028
21  0x103c59fda llint_entry
22  0x103c59fda llint_entry
23  0x103c59fda llint_entry
24  0x103c52b6e vmEntryToJavaScript
25  0x103a3419c JSC::JITCode::execute(JSC::VM*, JSC::ProtoCallFrame*)
26  0x1039b0aaf JSC::Interpreter::executeCall(JSC::ExecState*, JSC::JSObject*, JSC::CallType, JSC::CallData const&amp;, JSC::JSValue, JSC::ArgList const&amp;)
27  0x1031fc8de JSC::call(JSC::ExecState*, JSC::JSValue, JSC::CallType, JSC::CallData const&amp;, JSC::JSValue, JSC::ArgList const&amp;)
28  0x1031fc9b9 JSC::call(JSC::ExecState*, JSC::JSValue, JSC::CallType, JSC::CallData const&amp;, JSC::JSValue, JSC::ArgList const&amp;, WTF::NakedPtr&lt;JSC::Exception&gt;&amp;)
29  0x10a3cc62b WebCore::JSMainThreadExecState::call(JSC::ExecState*, JSC::JSValue, JSC::CallType, JSC::CallData const&amp;, JSC::JSValue, JSC::ArgList const&amp;, WTF::NakedPtr&lt;JSC::Exception&gt;&amp;)
30  0x10a7dbd4d WebCore::functionCallHandlerFromAnyThread(JSC::ExecState*, JSC::JSValue, JSC::CallType, JSC::CallData const&amp;, JSC::JSValue, JSC::ArgList const&amp;, WTF::NakedPtr&lt;JSC::Exception&gt;&amp;)
31  0x103e88288 Deprecated::ScriptFunctionCall::call(bool&amp;)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1239335</commentid>
    <comment_count>1</comment_count>
    <who name="Ryan Haddad">ryanhaddad</who>
    <bug_when>2016-10-12 09:53:54 -0700</bug_when>
    <thetext>Started with https://trac.webkit.org/changeset/207179</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1239336</commentid>
    <comment_count>2</comment_count>
    <who name="Ryan Haddad">ryanhaddad</who>
    <bug_when>2016-10-12 09:55:01 -0700</bug_when>
    <thetext>Seen with these tests on all mac debug builds:

inspector/console/heapSnapshot.html
inspector/timeline/setInstruments-programmatic-capture.html

https://build.webkit.org/results/Apple%20Sierra%20Debug%20WK2%20(Tests)/r207192%20(299)/results.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1239365</commentid>
    <comment_count>3</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2016-10-12 11:11:25 -0700</bug_when>
    <thetext>I have a fix!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1239373</commentid>
    <comment_count>4</comment_count>
      <attachid>291371</attachid>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2016-10-12 11:20:39 -0700</bug_when>
    <thetext>Created attachment 291371
the patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1239378</commentid>
    <comment_count>5</comment_count>
      <attachid>291371</attachid>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2016-10-12 11:26:04 -0700</bug_when>
    <thetext>Comment on attachment 291371
the patch

View in context: https://bugs.webkit.org/attachment.cgi?id=291371&amp;action=review

r=me

&gt; Source/JavaScriptCore/heap/HeapSnapshot.cpp:126
&gt;              ASSERT(node.cell != previousCell);

Should this be a RELEASE_ASSERT?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1239379</commentid>
    <comment_count>6</comment_count>
      <attachid>291371</attachid>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2016-10-12 11:27:05 -0700</bug_when>
    <thetext>Comment on attachment 291371
the patch

View in context: https://bugs.webkit.org/attachment.cgi?id=291371&amp;action=review

&gt;&gt; Source/JavaScriptCore/heap/HeapSnapshot.cpp:126
&gt;&gt;              ASSERT(node.cell != previousCell);
&gt; 
&gt; Should this be a RELEASE_ASSERT?

It could be.  But we&apos;re in a #ifndef NDEBUG block, so it wouldn&apos;t do any good.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1239658</commentid>
    <comment_count>7</comment_count>
    <who name="Mark Lam">mark.lam</who>
    <bug_when>2016-10-12 20:11:47 -0700</bug_when>
    <thetext>Patch was landed in r207230: &lt;https://trac.webkit.org/changeset/207230&gt;.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>291371</attachid>
            <date>2016-10-12 11:20:39 -0700</date>
            <delta_ts>2016-10-12 11:26:04 -0700</delta_ts>
            <desc>the patch</desc>
            <filename>blah.patch</filename>
            <type>text/plain</type>
            <size>2900</size>
            <attacher name="Filip Pizlo">fpizlo</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9DaGFuZ2VMb2cKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkocmV2aXNpb24gMjA3MjI1KQorKysgU291cmNl
L0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDI0IEBA
CisyMDE2LTEwLTEyICBGaWxpcCBQaXpsbyAgPGZwaXpsb0BhcHBsZS5jb20+CisKKyAgICAgICAg
UkVHUkVTU0lPTiAocjIwNzE3OSk6IEFTU0VSVElPTiBGQUlMRUQ6IG5vZGUuY2VsbCAhPSBwcmV2
aW91c0NlbGwKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lk
PTE2MzMzNworCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorICAgICAgICAK
KyAgICAgICAgSXQgdHVybnMgb3V0IHRoYXQgSGVhcFNuYXBzaG90IHdhcyBub3QgZG93biB3aXRo
IHJldmlzaXRpbmcuIFRoZSBjb25jdXJyZW50IEdDIGlzIGdvaW5nIHRvIGJlCisgICAgICAgIGJ1
aWx0IGFyb3VuZCB0aGUgaWRlYSB0aGF0IHdlIGNhbiByZXZpc2l0IG9iamVjdHMgbWFueSB0aW1l
cy4gVGhpcyBtZWFucyB0aGF0IGFueSBhY3Rpb24gdGhhdAorICAgICAgICBzaG91bGQgb25seSB0
YWtlIHBsYWNlIG9uY2UgcGVyIG9iamVjdCBtdXN0IGNoZWNrIHRoZSBvYmplY3QncyBzdGF0ZS4g
VGhpcyBmaXhlcyB0aGUgc25hcHNob3QKKyAgICAgICAgY29kZSB0byBkbyB0aGlzLgorICAgICAg
ICAKKyAgICAgICAgV2hpbGUgd3JpdGluZyB0aGlzIGNvZGUsIEkgcmVhbGl6ZWQgdGhhdCB3ZSdy
ZSBhY3R1YWxseSBkb2luZyB0aGlzIGNoZWNrIGluY29ycmVjdGx5LCBzbyBJCisgICAgICAgIGZp
bGVkIGJ1ZyAxNjMzNDMuIFRoYXQgYnVnIHJlcXVpcmVzIGEgcmFjZSwgc28gd2UgYXJlbid0IGdv
aW5nIHRvIHNlZSBpdCB5ZXQuCisKKyAgICAgICAgKiBoZWFwL0hlYXBTbmFwc2hvdC5jcHA6Cisg
ICAgICAgIChKU0M6OkhlYXBTbmFwc2hvdDo6ZmluYWxpemUpOgorICAgICAgICAqIGhlYXAvU2xv
dFZpc2l0b3IuY3BwOgorICAgICAgICAoSlNDOjpTbG90VmlzaXRvcjo6YXBwZW5kVG9NYXJrU3Rh
Y2spOgorICAgICAgICAoSlNDOjpTbG90VmlzaXRvcjo6dmlzaXRDaGlsZHJlbik6CisKIDIwMTYt
MTAtMTIgIEZpbGlwIFBpemxvICA8ZnBpemxvQGFwcGxlLmNvbT4KIAogICAgICAgICBSZW1vdmUg
SklUV3JpdGVCYXJyaWVyLmgKSW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9oZWFwL0hlYXBT
bmFwc2hvdC5jcHAKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291cmNlL0phdmFTY3JpcHRDb3JlL2hlYXAvSGVh
cFNuYXBzaG90LmNwcAkocmV2aXNpb24gMjA3MjIxKQorKysgU291cmNlL0phdmFTY3JpcHRDb3Jl
L2hlYXAvSGVhcFNuYXBzaG90LmNwcAkod29ya2luZyBjb3B5KQpAQCAtMTIxLDggKzEyMSwxMCBA
QCB2b2lkIEhlYXBTbmFwc2hvdDo6ZmluYWxpemUoKQogICAgIGZvciAoYXV0byYgbm9kZSA6IG1f
bm9kZXMpIHsKICAgICAgICAgQVNTRVJUKG5vZGUuY2VsbCk7CiAgICAgICAgIEFTU0VSVCghKHJl
aW50ZXJwcmV0X2Nhc3Q8aW50cHRyX3Q+KG5vZGUuY2VsbCkgJiBDZWxsVG9Td2VlcFRhZykpOwot
ICAgICAgICBpZiAocHJldmlvdXNDZWxsKQorICAgICAgICBpZiAobm9kZS5jZWxsID09IHByZXZp
b3VzQ2VsbCkgeworICAgICAgICAgICAgZGF0YUxvZygiU2VlaW5nIHNhbWUgY2VsbCB0d2ljZTog
IiwgUmF3UG9pbnRlcihwcmV2aW91c0NlbGwpLCAiXG4iKTsKICAgICAgICAgICAgIEFTU0VSVChu
b2RlLmNlbGwgIT0gcHJldmlvdXNDZWxsKTsKKyAgICAgICAgfQogICAgICAgICBwcmV2aW91c0Nl
bGwgPSBub2RlLmNlbGw7CiAgICAgfQogI2VuZGlmCkluZGV4OiBTb3VyY2UvSmF2YVNjcmlwdENv
cmUvaGVhcC9TbG90VmlzaXRvci5jcHAKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291cmNlL0phdmFTY3JpcHRD
b3JlL2hlYXAvU2xvdFZpc2l0b3IuY3BwCShyZXZpc2lvbiAyMDcyMjEpCisrKyBTb3VyY2UvSmF2
YVNjcmlwdENvcmUvaGVhcC9TbG90VmlzaXRvci5jcHAJKHdvcmtpbmcgY29weSkKQEAgLTIzNyw5
ICsyMzcsNiBAQCBBTFdBWVNfSU5MSU5FIHZvaWQgU2xvdFZpc2l0b3I6OmFwcGVuZFRvCiAgICAg
bV9ieXRlc1Zpc2l0ZWQgKz0gY29udGFpbmVyLmNlbGxTaXplKCk7CiAgICAgCiAgICAgbV9zdGFj
ay5hcHBlbmQoY2VsbCk7Ci0KLSAgICBpZiAoVU5MSUtFTFkobV9oZWFwU25hcHNob3RCdWlsZGVy
KSkKLSAgICAgICAgbV9oZWFwU25hcHNob3RCdWlsZGVyLT5hcHBlbmROb2RlKGNlbGwpOwogfQog
CiB2b2lkIFNsb3RWaXNpdG9yOjptYXJrQXV4aWxpYXJ5KGNvbnN0IHZvaWQqIGJhc2UpCkBAIC0z
MTksNiArMzE2LDExIEBAIEFMV0FZU19JTkxJTkUgdm9pZCBTbG90VmlzaXRvcjo6dmlzaXRDaGkK
ICAgICAgICAgY2VsbC0+bWV0aG9kVGFibGUoKS0+dmlzaXRDaGlsZHJlbihjb25zdF9jYXN0PEpT
Q2VsbCo+KGNlbGwpLCAqdGhpcyk7CiAgICAgICAgIGJyZWFrOwogICAgIH0KKyAgICAKKyAgICBp
ZiAoVU5MSUtFTFkobV9oZWFwU25hcHNob3RCdWlsZGVyKSkgeworICAgICAgICBpZiAoY2VsbC0+
Y2VsbFN0YXRlKCkgIT0gQ2VsbFN0YXRlOjpPbGRCbGFjaykKKyAgICAgICAgICAgIG1faGVhcFNu
YXBzaG90QnVpbGRlci0+YXBwZW5kTm9kZShjb25zdF9jYXN0PEpTQ2VsbCo+KGNlbGwpKTsKKyAg
ICB9CiB9CiAKIHZvaWQgU2xvdFZpc2l0b3I6OmRvbmF0ZUtub3duUGFyYWxsZWwoKQo=
</data>
<flag name="review"
          id="314510"
          type_id="1"
          status="+"
          setter="mark.lam"
    />
          </attachment>
      

    </bug>

</bugzilla>