Title: [203518] trunk/Source/WebCore
Revision
203518
Author
[email protected]
Date
2016-07-21 12:41:47 -0700 (Thu, 21 Jul 2016)

Log Message

Crash accessing null renderer inside WebCore::DeleteSelectionCommand::doApply
https://bugs.webkit.org/show_bug.cgi?id=160011

Reviewed by Chris Dumez.

Add a null pointer check for renderer() call.

Unfortunately no new tests since we don't have a reproduction.

* editing/DeleteSelectionCommand.cpp:
(WebCore::DeleteSelectionCommand::doApply):

Modified Paths

Diff

Modified: trunk/Source/WebCore/ChangeLog (203517 => 203518)


--- trunk/Source/WebCore/ChangeLog	2016-07-21 19:04:35 UTC (rev 203517)
+++ trunk/Source/WebCore/ChangeLog	2016-07-21 19:41:47 UTC (rev 203518)
@@ -1,3 +1,17 @@
+2016-07-21  Ryosuke Niwa  <[email protected]>
+
+        Crash accessing null renderer inside WebCore::DeleteSelectionCommand::doApply
+        https://bugs.webkit.org/show_bug.cgi?id=160011
+
+        Reviewed by Chris Dumez.
+
+        Add a null pointer check for renderer() call.
+
+        Unfortunately no new tests since we don't have a reproduction.
+
+        * editing/DeleteSelectionCommand.cpp:
+        (WebCore::DeleteSelectionCommand::doApply):
+
 2016-07-21  Chris Dumez  <[email protected]>
 
         The 2 first parameters to DOMImplementation.createDocument() should be mandatory

Modified: trunk/Source/WebCore/editing/DeleteSelectionCommand.cpp (203517 => 203518)


--- trunk/Source/WebCore/editing/DeleteSelectionCommand.cpp	2016-07-21 19:04:35 UTC (rev 203517)
+++ trunk/Source/WebCore/editing/DeleteSelectionCommand.cpp	2016-07-21 19:41:47 UTC (rev 203518)
@@ -864,7 +864,7 @@
         Node* node = m_endingPosition.deprecatedNode();
         if (is<Text>(node)) {
             Text& textNode = downcast<Text>(*node);
-            if (textNode.length())
+            if (textNode.length() && textNode.renderer())
                 shouldRebalaceWhiteSpace = textNode.renderer()->style().textSecurity() == TSNONE;
         }        
     }
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to