Title: [278398] trunk
- Revision
- 278398
- Author
- [email protected]
- Date
- 2021-06-03 00:09:28 -0700 (Thu, 03 Jun 2021)
Log Message
Crash in HTMLConverter::_addLinkForElement()
https://bugs.webkit.org/show_bug.cgi?id=226398
Patch by Julian Gonzalez <[email protected]> on 2021-06-03
Reviewed by Ryosuke Niwa.
Source/WebCore:
While traversing a node, exit an element with a startIndex
that is always inside the bounds of the attribute string.
Test: editing/pasteboard/select-all-link-cut.html
* editing/cocoa/HTMLConverter.mm:
(HTMLConverter::_traverseNode):
LayoutTests:
Add a test for this crasher.
* editing/pasteboard/select-all-link-cut-expected.txt: Added.
* editing/pasteboard/select-all-link-cut.html: Added.
Modified Paths
Added Paths
Diff
Modified: trunk/LayoutTests/ChangeLog (278397 => 278398)
--- trunk/LayoutTests/ChangeLog 2021-06-03 06:50:32 UTC (rev 278397)
+++ trunk/LayoutTests/ChangeLog 2021-06-03 07:09:28 UTC (rev 278398)
@@ -1,3 +1,15 @@
+2021-06-03 Julian Gonzalez <[email protected]>
+
+ Crash in HTMLConverter::_addLinkForElement()
+ https://bugs.webkit.org/show_bug.cgi?id=226398
+
+ Reviewed by Ryosuke Niwa.
+
+ Add a test for this crasher.
+
+ * editing/pasteboard/select-all-link-cut-expected.txt: Added.
+ * editing/pasteboard/select-all-link-cut.html: Added.
+
2021-06-02 Alex Christensen <[email protected]>
Fix WPT test resource-timing/cross-origin-redirects.html
Added: trunk/LayoutTests/editing/pasteboard/select-all-link-cut-expected.txt (0 => 278398)
--- trunk/LayoutTests/editing/pasteboard/select-all-link-cut-expected.txt (rev 0)
+++ trunk/LayoutTests/editing/pasteboard/select-all-link-cut-expected.txt 2021-06-03 07:09:28 UTC (rev 278398)
@@ -0,0 +1 @@
+This test passes if WebKit does not crash. PASS
Added: trunk/LayoutTests/editing/pasteboard/select-all-link-cut.html (0 => 278398)
--- trunk/LayoutTests/editing/pasteboard/select-all-link-cut.html (rev 0)
+++ trunk/LayoutTests/editing/pasteboard/select-all-link-cut.html 2021-06-03 07:09:28 UTC (rev 278398)
@@ -0,0 +1,27 @@
+<!DOCTYPE html>
+<html>
+<head>
+<script>
+if (window.testRunner)
+ testRunner.dumpAsText();
+
+document.designMode = 'on';
+function runtest() {
+ document.execCommand("selectAll", false);
+ document.execCommand("createLink", false, "test");
+ document.execCommand("cut", false);
+ document.write('This test passes if WebKit does not crash. PASS');
+}
+</script>
+</head>
+<body>
+</a>
+This test passes if WebKit does not crash.
+<style _onload_="runtest()"></style>
+</a>
+<ol contenteditable="false" hidden="hidden">
+<li></li>
+</ol>
+<iframe></iframe>
+</body>
+</html>
Modified: trunk/Source/WebCore/ChangeLog (278397 => 278398)
--- trunk/Source/WebCore/ChangeLog 2021-06-03 06:50:32 UTC (rev 278397)
+++ trunk/Source/WebCore/ChangeLog 2021-06-03 07:09:28 UTC (rev 278398)
@@ -1,3 +1,18 @@
+2021-06-03 Julian Gonzalez <[email protected]>
+
+ Crash in HTMLConverter::_addLinkForElement()
+ https://bugs.webkit.org/show_bug.cgi?id=226398
+
+ Reviewed by Ryosuke Niwa.
+
+ While traversing a node, exit an element with a startIndex
+ that is always inside the bounds of the attribute string.
+
+ Test: editing/pasteboard/select-all-link-cut.html
+
+ * editing/cocoa/HTMLConverter.mm:
+ (HTMLConverter::_traverseNode):
+
2021-06-02 Rob Buis <[email protected]>
Make EndTransparancyLayer a potential no-op
Modified: trunk/Source/WebCore/editing/cocoa/HTMLConverter.mm (278397 => 278398)
--- trunk/Source/WebCore/editing/cocoa/HTMLConverter.mm 2021-06-03 06:50:32 UTC (rev 278397)
+++ trunk/Source/WebCore/editing/cocoa/HTMLConverter.mm 2021-06-03 07:09:28 UTC (rev 278398)
@@ -2216,7 +2216,7 @@
child = nextSiblingInComposedTreeIgnoringUserAgentShadow(*child);
}
}
- _exitElement(element, depth, startIndex);
+ _exitElement(element, depth, std::min(startIndex, [_attrStr length]));
}
}
} else if (node.nodeType() == Node::TEXT_NODE)
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes