The following testcases, when passed in as a CLI argument to the js shell, show weird output on TM changeset e8ee411dca70 with -j. Filing together because they were reduced from the same large testcase, s-s because they involve gc..
The testcases have been attached, and are private because they still have a large part of jsfunfuzz in them. They have been a PITA to reduce. :(
Probably related to bug 558451. Regression window: http://hg.mozilla.org/tracemonkey/pushloghtml?fromchange=be9979b4c10b&tochange=f3e58c264932
Isn't jsfunfuzz public? http://www.squarefree.com/2007/08/02/introducing-jsfunfuzz/
Older versions of jsfunfuzz are public, yes.
WFM, another bisect candidate. I bet bug 595365 had the fix-patch but out of time to research atm. /be
The first good revision is: changeset: 51614:e80892986b11 user: Brendan Eich <email@example.com> date: Tue Aug 31 07:33:25 2010 -0700 summary: Bug 592001 - Fix v8-regexp regression in wake of patch for bug 558451 (r=igor, CLOSED TREE). The testcase is messy, so this may or may not have been the changeset that actually fixed the bug.