Title: [203518] trunk/Source/WebCore
- Revision
- 203518
- Author
- [email protected]
- Date
- 2016-07-21 12:41:47 -0700 (Thu, 21 Jul 2016)
Log Message
Crash accessing null renderer inside WebCore::DeleteSelectionCommand::doApply
https://bugs.webkit.org/show_bug.cgi?id=160011
Reviewed by Chris Dumez.
Add a null pointer check for renderer() call.
Unfortunately no new tests since we don't have a reproduction.
* editing/DeleteSelectionCommand.cpp:
(WebCore::DeleteSelectionCommand::doApply):
Modified Paths
Diff
Modified: trunk/Source/WebCore/ChangeLog (203517 => 203518)
--- trunk/Source/WebCore/ChangeLog 2016-07-21 19:04:35 UTC (rev 203517)
+++ trunk/Source/WebCore/ChangeLog 2016-07-21 19:41:47 UTC (rev 203518)
@@ -1,3 +1,17 @@
+2016-07-21 Ryosuke Niwa <[email protected]>
+
+ Crash accessing null renderer inside WebCore::DeleteSelectionCommand::doApply
+ https://bugs.webkit.org/show_bug.cgi?id=160011
+
+ Reviewed by Chris Dumez.
+
+ Add a null pointer check for renderer() call.
+
+ Unfortunately no new tests since we don't have a reproduction.
+
+ * editing/DeleteSelectionCommand.cpp:
+ (WebCore::DeleteSelectionCommand::doApply):
+
2016-07-21 Chris Dumez <[email protected]>
The 2 first parameters to DOMImplementation.createDocument() should be mandatory
Modified: trunk/Source/WebCore/editing/DeleteSelectionCommand.cpp (203517 => 203518)
--- trunk/Source/WebCore/editing/DeleteSelectionCommand.cpp 2016-07-21 19:04:35 UTC (rev 203517)
+++ trunk/Source/WebCore/editing/DeleteSelectionCommand.cpp 2016-07-21 19:41:47 UTC (rev 203518)
@@ -864,7 +864,7 @@
Node* node = m_endingPosition.deprecatedNode();
if (is<Text>(node)) {
Text& textNode = downcast<Text>(*node);
- if (textNode.length())
+ if (textNode.length() && textNode.renderer())
shouldRebalaceWhiteSpace = textNode.renderer()->style().textSecurity() == TSNONE;
}
}
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes