<html>
    <head>
      <base href="https://bugs.webkit.org/" />
    </head>
    <body><table border="1" cellspacing="0" cellpadding="8">
        <tr>
          <th>Bug ID</th>
          <td><a class="bz_bug_link 
          bz_status_NEW "
   title="NEW - CrashOnOverflow in JSC::Yarr::YarrPatternConstructor::setupAlternativeOffsets"
   href="https://bugs.webkit.org/show_bug.cgi?id=159954">159954</a>
          </td>
        </tr>

        <tr>
          <th>Summary</th>
          <td>CrashOnOverflow in JSC::Yarr::YarrPatternConstructor::setupAlternativeOffsets
          </td>
        </tr>

        <tr>
          <th>Classification</th>
          <td>Unclassified
          </td>
        </tr>

        <tr>
          <th>Product</th>
          <td>WebKit
          </td>
        </tr>

        <tr>
          <th>Version</th>
          <td>WebKit Nightly Build
          </td>
        </tr>

        <tr>
          <th>Hardware</th>
          <td>Unspecified
          </td>
        </tr>

        <tr>
          <th>OS</th>
          <td>Unspecified
          </td>
        </tr>

        <tr>
          <th>Status</th>
          <td>NEW
          </td>
        </tr>

        <tr>
          <th>Severity</th>
          <td>Normal
          </td>
        </tr>

        <tr>
          <th>Priority</th>
          <td>P2
          </td>
        </tr>

        <tr>
          <th>Component</th>
          <td>JavaScriptCore
          </td>
        </tr>

        <tr>
          <th>Assignee</th>
          <td>webkit-unassigned&#64;lists.webkit.org
          </td>
        </tr>

        <tr>
          <th>Reporter</th>
          <td>msaboff&#64;apple.com
          </td>
        </tr></table>
      <p>
        <div>
        <pre>We are failing on regular expressions that exceed 2^32 characters.  For example:
  /a{2147483649,2147483650}a{2147483649,2147483650}/

Backtraces look something like:
    #0 0x10a0d2cb8 in WTFCrash (JavaScriptCore+0x2a87cb8)
    #1 0x10766291d in WTF::CrashOnOverflow::crash() (JavaScriptCore+0x1791d)
    #2 0x1076628bd in WTF::CrashOnOverflow::overflowed() (JavaScriptCore+0x178bd)
    #3 0x10a0ab684 in WTF::Checked&lt;unsigned int, WTF::CrashOnOverflow&gt; const WTF::Checked&lt;unsigned int, WTF::CrashOnOverflow&gt;::operator+=&lt;unsigned int&gt;(unsigned int) (JavaScriptCore+0x2a60684)
    #4 0x10a0ab0b0 in WTF::Checked&lt;unsigned int, WTF::CrashOnOverflow&gt; const WTF::Checked&lt;unsigned int, WTF::CrashOnOverflow&gt;::operator+=&lt;unsigned int, WTF::CrashOnOverflow&gt;(WTF::Checked&lt;unsigned int, WTF::CrashOnOverflow&gt;) (JavaScriptCore+0x2a600b0)
    #5 0x10a0a9f6a in JSC::Yarr::YarrPatternConstructor::setupAlternativeOffsets(JSC::Yarr::PatternAlternative*, unsigned int, unsigned int, unsigned int&amp;) (JavaScriptCore+0x2a5ef6a)
    #6 0x10a0a8035 in JSC::Yarr::YarrPatternConstructor::setupDisjunctionOffsets(JSC::Yarr::PatternDisjunction*, unsigned int, unsigned int, unsigned int&amp;) (JavaScriptCore+0x2a5d035)
    #7 0x10a0aa835 in JSC::Yarr::YarrPatternConstructor::setupAlternativeOffsets(JSC::Yarr::PatternAlternative*, unsigned int, unsigned int, unsigned int&amp;) (JavaScriptCore+0x2a5f835)
    #8 0x10a0a8035 in JSC::Yarr::YarrPatternConstructor::setupDisjunctionOffsets(JSC::Yarr::PatternDisjunction*, unsigned int, unsigned int, unsigned int&amp;) (JavaScriptCore+0x2a5d035)
    #9 0x10a09d9f2 in JSC::Yarr::YarrPatternConstructor::setupOffsets() (JavaScriptCore+0x2a529f2)
    #10 0x10a09ba89 in JSC::Yarr::YarrPattern::compile(WTF::String const&amp;, void*) (JavaScriptCore+0x2a50a89)
    ...</pre>
        </div>
      </p>
      <hr>
      <span>You are receiving this mail because:</span>
      
      <ul>
          <li>You are the assignee for the bug.</li>
      </ul>
    </body>
</html>