[Webkit-unassigned] [Bug 13801] Crash when loading nonexisting symbol

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Mon May 21 23:41:32 PDT 2007


http://bugs.webkit.org/show_bug.cgi?id=13801


ddkilzer at webkit.org changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|UNCONFIRMED                 |NEW
     Ever Confirmed|0                           |1
           Priority|P2                          |P1




------- Comment #2 from ddkilzer at webkit.org  2007-05-21 23:41 PDT -------
Confirmed with a local debug build of WebKit r21608 with Safari 2.0.4 (419.3)
on Mac OS X 10.4.9 (8P135).

Console output:

ASSERTION FAILED: target
(/path/to/WebKit/WebCore/ksvg2/svg/SVGUseElement.cpp:242 virtual void
WebCore::SVGUseElement::buildPendingResource())
Segmentation fault

Stack trace:

Exception:  EXC_BAD_ACCESS (0x0001)
Codes:      KERN_INVALID_ADDRESS (0x0001) at 0xbbadbeef

Thread 0 Crashed:
0   com.apple.WebCore           0x010c85f4
WebCore::SVGUseElement::buildPendingResource() + 376 (SVGUseElement.cpp:242)
1   com.apple.WebCore           0x010c5280
WebCore::SVGUseElement::attributeChanged(WebCore::Attribute*, bool) + 352
(SVGUseElement.cpp:149)
2   com.apple.WebCore           0x012d38ec
WebCore::Element::setAttribute(WebCore::QualifiedName const&,
WebCore::StringImpl*, int&) + 600 (Element.cpp:478)
3   com.apple.WebCore           0x012d39f0
WebCore::Element::setAttributeNS(WebCore::String const&, WebCore::String
const&, WebCore::String const&, int&) + 240 (Element.cpp:907)
4   com.apple.WebCore           0x012bccf0
WebCore::JSElementPrototypeFunction::callAsFunction(KJS::ExecState*,
KJS::JSObject*, KJS::List const&) + 2112 (JSElement.cpp:344)
5   com.apple.JavaScriptCore    0x00583690 KJS::JSObject::call(KJS::ExecState*,
KJS::JSObject*, KJS::List const&) + 288 (object.cpp:98)
6   com.apple.JavaScriptCore    0x005b4d3c
KJS::FunctionCallDotNode::evaluate(KJS::ExecState*) + 992 (nodes.cpp:790)
7   com.apple.JavaScriptCore    0x005b13fc
KJS::ExprStatementNode::execute(KJS::ExecState*) + 220 (nodes.cpp:1723)
8   com.apple.JavaScriptCore    0x005adbec
KJS::SourceElementsNode::execute(KJS::ExecState*) + 284 (nodes.cpp:2523)
9   com.apple.JavaScriptCore    0x0057f1a0
KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:1700)
10  com.apple.JavaScriptCore    0x0057f2f0
KJS::DeclaredFunctionImp::execute(KJS::ExecState*) + 92 (function.cpp:319)
11  com.apple.JavaScriptCore    0x0059eab8
KJS::FunctionImp::callAsFunction(KJS::ExecState*, KJS::JSObject*, KJS::List
const&) + 688 (function.cpp:107)
12  com.apple.JavaScriptCore    0x00583690 KJS::JSObject::call(KJS::ExecState*,
KJS::JSObject*, KJS::List const&) + 288 (object.cpp:98)
13  com.apple.JavaScriptCore    0x005b5588
KJS::FunctionCallResolveNode::evaluate(KJS::ExecState*) + 792 (nodes.cpp:694)
14  com.apple.JavaScriptCore    0x005b13fc
KJS::ExprStatementNode::execute(KJS::ExecState*) + 220 (nodes.cpp:1723)
15  com.apple.JavaScriptCore    0x005adbec
KJS::SourceElementsNode::execute(KJS::ExecState*) + 284 (nodes.cpp:2523)
16  com.apple.JavaScriptCore    0x0057f1a0
KJS::BlockNode::execute(KJS::ExecState*) + 216 (nodes.cpp:1700)
17  com.apple.JavaScriptCore    0x005aa594
KJS::Interpreter::evaluate(KJS::UString const&, int, KJS::UChar const*, int,
KJS::JSValue*) + 1116 (interpreter.cpp:365)
18  com.apple.WebCore           0x012fa51c
WebCore::KJSProxy::evaluate(WebCore::String const&, int, WebCore::String
const&, WebCore::Node*) + 420 (kjs_proxy.cpp:78)
19  com.apple.WebCore           0x014a456c
WebCore::FrameLoader::executeScript(WebCore::String const&, int,
WebCore::Node*, WebCore::String const&) + 136 (FrameLoader.cpp:732)
20  com.apple.WebCore           0x014a4650
WebCore::FrameLoader::executeScript(WebCore::Node*, WebCore::String const&,
bool) + 144 (FrameLoader.cpp:720)
21  com.apple.WebCore           0x013030f8
KJS::ScheduledAction::execute(KJS::Window*) + 1092 (kjs_window.cpp:1921)
22  com.apple.WebCore           0x01306490
KJS::Window::timerFired(KJS::DOMWindowTimer*) + 104 (kjs_window.cpp:2024)
23  com.apple.WebCore           0x013066b8 KJS::DOMWindowTimer::fired() + 72
(kjs_window.cpp:2628)
24  com.apple.WebCore           0x01280a98
WebCore::TimerBase::fireTimers(double, WTF::Vector<WebCore::TimerBase*,
(unsigned long)0> const&) + 236 (Timer.cpp:322)
25  com.apple.WebCore           0x01280b64
WebCore::TimerBase::sharedTimerFired() + 132 (Timer.cpp:355)
26  com.apple.WebCore           0x0127ff10
WebCore::timerFired(__CFRunLoopTimer*, void*) + 60 (SharedTimerMac.cpp:47)
27  com.apple.CoreFoundation    0x907f2578 __CFRunLoopDoTimer + 184
28  com.apple.CoreFoundation    0x907deef8 __CFRunLoopRun + 1680
29  com.apple.CoreFoundation    0x907de4ac CFRunLoopRunSpecific + 268
30  com.apple.HIToolbox         0x9329bb20 RunCurrentEventLoopInMode + 264
31  com.apple.HIToolbox         0x9329b1b4 ReceiveNextEventCommon + 380
32  com.apple.HIToolbox         0x9329b020
BlockUntilNextEventMatchingListInMode + 96
33  com.apple.AppKit            0x937a1ae4 _DPSNextEvent + 384
34  com.apple.AppKit            0x937a17a8 -[NSApplication
nextEventMatchingMask:untilDate:inMode:dequeue:] + 116
35  com.apple.Safari            0x00006740 0x1000 + 22336
36  com.apple.AppKit            0x9379dcec -[NSApplication run] + 472
37  com.apple.AppKit            0x9388e87c NSApplicationMain + 452
38  com.apple.Safari            0x0005c77c 0x1000 + 374652
39  com.apple.Safari            0x0005c624 0x1000 + 374308


-- 
Configure bugmail: http://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.



More information about the webkit-unassigned mailing list