<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>189830</bug_id>
          
          <creation_ts>2018-09-21 07:15:22 -0700</creation_ts>
          <short_desc>REGRESSION: crash under JSC::JSRopeString::resolveRope(JSC::ExecState*)</short_desc>
          <delta_ts>2018-09-22 15:17:19 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>JavaScriptCore</component>
          <version>Safari Technology Preview</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <dup_id>189855</dup_id>
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Antoine Quint">graouts</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1461828</commentid>
    <comment_count>0</comment_count>
    <who name="Antoine Quint">graouts</who>
    <bug_when>2018-09-21 07:15:22 -0700</bug_when>
    <thetext>On a ToT Release build, going to this URL yields a WebContent crash:

http://loanpride.com/ces-enfants-de-stars-sont-devenus-grands-ils-peuvent-maintenant-construire-leur-vie-future-grace-a-leur-conseillers-financiers/

0   com.apple.JavaScriptCore      	0x00000004bcde023e JSC::JSRopeString::resolveRope(JSC::ExecState*) const + 318 (MarkedBlock.h:447)
1   com.apple.JavaScriptCore      	0x00000004bcd755b8 JSC::getCalculatedDisplayName(JSC::VM&amp;, JSC::JSObject*) + 424 (RefPtr.h:59)
2   com.apple.JavaScriptCore      	0x00000004bce7b51b JSC::StackFrame::functionName(JSC::VM&amp;) const + 107 (DumbPtrTraits.h:41)
3   com.apple.JavaScriptCore      	0x00000004bce7b684 JSC::StackFrame::toString(JSC::VM&amp;) const + 52 (StackFrame.cpp:63)
4   com.apple.JavaScriptCore      	0x00000004bcac8dc7 JSC::Interpreter::stackTraceAsString(JSC::VM&amp;, WTF::Vector&lt;JSC::StackFrame, 0ul, WTF::CrashOnOverflow, 16ul&gt; const&amp;) + 135 (Interpreter.cpp:460)
5   com.apple.JavaScriptCore      	0x00000004bcd185f4 JSC::addErrorInfo(JSC::VM&amp;, WTF::Vector&lt;JSC::StackFrame, 0ul, WTF::CrashOnOverflow, 16ul&gt;*, JSC::JSObject*) + 612 (RefPtr.h:88)
6   com.apple.JavaScriptCore      	0x00000004bcd187b2 JSC::addErrorInfo(JSC::ExecState*, JSC::JSObject*, bool) + 162 (Error.cpp:236)
7   com.apple.WebCore             	0x00000004b8a020f5 WebCore::createDOMException(JSC::ExecState*, WebCore::ExceptionCode, WTF::String const&amp;) + 421 (JSDOMExceptionHandling.cpp:153)
8   com.apple.WebCore             	0x00000004b8a02267 WebCore::throwSecurityError(JSC::ExecState&amp;, JSC::ThrowScope&amp;, WTF::String const&amp;) + 23 (ThrowScope.h:81)
9   com.apple.WebCore             	0x00000004b8a08f39 bool WebCore::jsDOMWindowGetOwnPropertySlotRestrictedAccess&lt;(WebCore::DOMWindowType)0&gt;(WebCore::JSDOMGlobalObject*, WebCore::AbstractDOMWindow&amp;, JSC::ExecState&amp;, JSC::PropertyName, JSC::PropertySlot&amp;, WTF::String const&amp;) + 201 (PropertySlot.h:355)
10  com.apple.WebCore             	0x00000004b8a09e50 WebCore::JSDOMWindow::getOwnPropertySlot(JSC::JSObject*, JSC::ExecState*, JSC::PropertyName, JSC::PropertySlot&amp;) + 512 (JSDOMWindowCustom.cpp:204)
11  com.apple.JavaScriptCore      	0x00000004bcb9289a llint_slow_path_get_by_id + 3018 (JSObjectInlines.h:151)
12  com.apple.JavaScriptCore      	0x00000004bc4ec714 llint_entry + 11553 (LowLevelInterpreter64.asm:307)
13  com.apple.JavaScriptCore      	0x00000004bc4f02b4 llint_entry + 26817 (LowLevelInterpreter.asm:831)
14  ???                           	0x00003dd69a06ed77 0 + 67991916440951
15  ???                           	0x00003dd69a086ee3 0 + 67991916539619
16  ???                           	0x00003dd69a0b3b26 0 + 67991916722982
17  ???                           	0x00003dd69a052254 0 + 67991916323412
18  ???                           	0x00003dd69a088ec3 0 + 67991916547779
19  ???                           	0x00003dd69a0b3b26 0 + 67991916722982
20  com.apple.JavaScriptCore      	0x00000004bc4f02b4 llint_entry + 26817 (LowLevelInterpreter.asm:831)
21  ???                           	0x00003dd69a086ee3 0 + 67991916539619
22  ???                           	0x00003dd69a0b3b26 0 + 67991916722982
23  com.apple.JavaScriptCore      	0x00000004bc4f02b4 llint_entry + 26817 (LowLevelInterpreter.asm:831)
24  com.apple.JavaScriptCore      	0x00000004bc4f02b4 llint_entry + 26817 (LowLevelInterpreter.asm:831)
25  com.apple.JavaScriptCore      	0x00000004bc4f02b4 llint_entry + 26817 (LowLevelInterpreter.asm:831)
26  com.apple.JavaScriptCore      	0x00000004bc4f0647 llint_entry + 27732 (LowLevelInterpreter.asm:831)
27  ???                           	0x00003dd699e4b73c 0 + 67991914198844
28  ???                           	0x00003dd69a057f31 0 + 67991916347185
29  ???                           	0x00003dd69a086ee3 0 + 67991916539619
30  ???                           	0x00003dd69a054835 0 + 67991916333109
31  ???                           	0x00003dd69a052254 0 + 67991916323412
32  ???                           	0x00003dd69a03d455 0 + 67991916237909
33  ???                           	0x00003dd69a057f31 0 + 67991916347185
34  ???                           	0x00003dd69a06c56a 0 + 67991916430698
35  ???                           	0x00003dd69a02c4c2 0 + 67991916168386
36  com.apple.JavaScriptCore      	0x00000004bc4f02b4 llint_entry + 26817 (LowLevelInterpreter.asm:831)
37  com.apple.JavaScriptCore      	0x00000004bc4e9839 vmEntryToJavaScript + 200 (LowLevelInterpreter64.asm:258)
38  com.apple.JavaScriptCore      	0x00000004bcacbc5c JSC::Interpreter::executeProgram(JSC::SourceCode const&amp;, JSC::ExecState*, JSC::JSObject*) + 11020 (JITCodeInlines.h:39)
39  com.apple.JavaScriptCore      	0x00000004bcd0696f JSC::evaluate(JSC::ExecState*, JSC::SourceCode const&amp;, JSC::JSValue, WTF::NakedPtr&lt;JSC::Exception&gt;&amp;) + 287 (Completion.cpp:103)
40  com.apple.WebCore             	0x00000004b8a27274 WebCore::JSExecState::profiledEvaluate(JSC::ExecState*, JSC::ProfilingReason, JSC::SourceCode const&amp;, JSC::JSValue, WTF::NakedPtr&lt;JSC::Exception&gt;&amp;) + 84 (JSExecState.h:80)
41  com.apple.WebCore             	0x00000004b8a270df WebCore::ScriptController::evaluateInWorld(WebCore::ScriptSourceCode const&amp;, WebCore::DOMWrapperWorld&amp;, WebCore::ExceptionDetails*) + 207 (ScriptController.cpp:131)
42  com.apple.WebCore             	0x00000004b8cae4e3 WebCore::ScriptElement::executeClassicScript(WebCore::ScriptSourceCode const&amp;) + 563 (CurrentScriptIncrementer.h:54)
43  com.apple.WebCore             	0x00000004b8c7ca1d WebCore::LoadableClassicScript::execute(WebCore::ScriptElement&amp;) + 141 (utility:896)
44  com.apple.WebCore             	0x00000004b8cae741 WebCore::ScriptElement::executeScriptAndDispatchEvent(WebCore::LoadableScript&amp;) + 177 (ScriptElement.cpp:427)
45  com.apple.WebCore             	0x00000004b8cb492d WebCore::ScriptRunner::timerFired() + 605 (ScriptRunner.cpp:132)
46  com.apple.WebCore             	0x00000004b91488c9 WebCore::ThreadTimers::sharedTimerFiredInternal() + 185 (ThreadTimers.cpp:120)
47  com.apple.WebCore             	0x00000004b918fcaf WebCore::timerFired(__CFRunLoopTimer*, void*) + 31 (MainThreadSharedTimerCF.cpp:75)
48  com.apple.CoreFoundation      	0x00007fff371bae6d __CFRUNLOOP_IS_CALLING_OUT_TO_A_TIMER_CALLBACK_FUNCTION__ + 20
49  com.apple.CoreFoundation      	0x00007fff371baa20 __CFRunLoopDoTimer + 859
50  com.apple.CoreFoundation      	0x00007fff371ba560 __CFRunLoopDoTimers + 333
51  com.apple.CoreFoundation      	0x00007fff3719b7b7 __CFRunLoopRun + 2176
52  com.apple.CoreFoundation      	0x00007fff3719ace4 CFRunLoopRunSpecific + 463
53  com.apple.Foundation          	0x00007fff394fb5da -[NSRunLoop(NSRunLoop) runMode:beforeDate:] + 280
54  com.apple.Foundation          	0x00007fff394fb4af -[NSRunLoop(NSRunLoop) run] + 76
55  libxpc.dylib                  	0x00007fff645eaee6 _xpc_objc_main + 555
56  libxpc.dylib                  	0x00007fff645ea9e5 xpc_main + 433
57  com.apple.WebKit.WebContent   	0x00000001040e7636 WebKit::XPCServiceMain(int, char const**) + 547
58  com.apple.WebKit.WebContent   	0x00000001040e77bb main + 9 (XPCServiceMain.mm:46)
59  libdyld.dylib                 	0x00007fff643b4085 start + 1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1461829</commentid>
    <comment_count>1</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2018-09-21 07:15:40 -0700</bug_when>
    <thetext>&lt;rdar://problem/44678975&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1461830</commentid>
    <comment_count>2</comment_count>
    <who name="Antoine Quint">graouts</who>
    <bug_when>2018-09-21 07:16:19 -0700</bug_when>
    <thetext>This does not appear to reproduce in STP 65, so this is likely a recent regression.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1462420</commentid>
    <comment_count>3</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2018-09-22 15:17:19 -0700</bug_when>
    <thetext>Yes, recent regression. Sounds like it was quickly fixed in bug 189855.

*** This bug has been marked as a duplicate of bug 189855 ***</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>