Title: [278398] trunk
Revision
278398
Author
[email protected]
Date
2021-06-03 00:09:28 -0700 (Thu, 03 Jun 2021)

Log Message

Crash in HTMLConverter::_addLinkForElement()
https://bugs.webkit.org/show_bug.cgi?id=226398

Patch by Julian Gonzalez <[email protected]> on 2021-06-03
Reviewed by Ryosuke Niwa.

Source/WebCore:

While traversing a node, exit an element with a startIndex
that is always inside the bounds of the attribute string.

Test: editing/pasteboard/select-all-link-cut.html

* editing/cocoa/HTMLConverter.mm:
(HTMLConverter::_traverseNode):

LayoutTests:

Add a test for this crasher.

* editing/pasteboard/select-all-link-cut-expected.txt: Added.
* editing/pasteboard/select-all-link-cut.html: Added.

Modified Paths

Added Paths

Diff

Modified: trunk/LayoutTests/ChangeLog (278397 => 278398)


--- trunk/LayoutTests/ChangeLog	2021-06-03 06:50:32 UTC (rev 278397)
+++ trunk/LayoutTests/ChangeLog	2021-06-03 07:09:28 UTC (rev 278398)
@@ -1,3 +1,15 @@
+2021-06-03  Julian Gonzalez  <[email protected]>
+
+        Crash in HTMLConverter::_addLinkForElement()
+        https://bugs.webkit.org/show_bug.cgi?id=226398
+
+        Reviewed by Ryosuke Niwa.
+
+        Add a test for this crasher.
+
+        * editing/pasteboard/select-all-link-cut-expected.txt: Added.
+        * editing/pasteboard/select-all-link-cut.html: Added.
+
 2021-06-02  Alex Christensen  <[email protected]>
 
         Fix WPT test resource-timing/cross-origin-redirects.html

Added: trunk/LayoutTests/editing/pasteboard/select-all-link-cut-expected.txt (0 => 278398)


--- trunk/LayoutTests/editing/pasteboard/select-all-link-cut-expected.txt	                        (rev 0)
+++ trunk/LayoutTests/editing/pasteboard/select-all-link-cut-expected.txt	2021-06-03 07:09:28 UTC (rev 278398)
@@ -0,0 +1 @@
+This test passes if WebKit does not crash. PASS

Added: trunk/LayoutTests/editing/pasteboard/select-all-link-cut.html (0 => 278398)


--- trunk/LayoutTests/editing/pasteboard/select-all-link-cut.html	                        (rev 0)
+++ trunk/LayoutTests/editing/pasteboard/select-all-link-cut.html	2021-06-03 07:09:28 UTC (rev 278398)
@@ -0,0 +1,27 @@
+<!DOCTYPE html>
+<html>
+<head>
+<script>
+if (window.testRunner)
+    testRunner.dumpAsText();
+
+document.designMode = 'on';
+function runtest() {
+    document.execCommand("selectAll", false);
+    document.execCommand("createLink", false, "test");
+    document.execCommand("cut", false);
+    document.write('This test passes if WebKit does not crash. PASS');
+}
+</script>
+</head>
+<body>
+</a>
+This test passes if WebKit does not crash.
+<style _onload_="runtest()"></style>
+</a>
+<ol contenteditable="false" hidden="hidden">
+<li></li>
+</ol>
+<iframe></iframe>
+</body>
+</html>

Modified: trunk/Source/WebCore/ChangeLog (278397 => 278398)


--- trunk/Source/WebCore/ChangeLog	2021-06-03 06:50:32 UTC (rev 278397)
+++ trunk/Source/WebCore/ChangeLog	2021-06-03 07:09:28 UTC (rev 278398)
@@ -1,3 +1,18 @@
+2021-06-03  Julian Gonzalez  <[email protected]>
+
+        Crash in HTMLConverter::_addLinkForElement()
+        https://bugs.webkit.org/show_bug.cgi?id=226398
+
+        Reviewed by Ryosuke Niwa.
+
+        While traversing a node, exit an element with a startIndex
+        that is always inside the bounds of the attribute string.
+
+        Test: editing/pasteboard/select-all-link-cut.html
+
+        * editing/cocoa/HTMLConverter.mm:
+        (HTMLConverter::_traverseNode):
+
 2021-06-02  Rob Buis  <[email protected]>
 
         Make EndTransparancyLayer a potential no-op

Modified: trunk/Source/WebCore/editing/cocoa/HTMLConverter.mm (278397 => 278398)


--- trunk/Source/WebCore/editing/cocoa/HTMLConverter.mm	2021-06-03 06:50:32 UTC (rev 278397)
+++ trunk/Source/WebCore/editing/cocoa/HTMLConverter.mm	2021-06-03 07:09:28 UTC (rev 278398)
@@ -2216,7 +2216,7 @@
                         child = nextSiblingInComposedTreeIgnoringUserAgentShadow(*child);
                     }
                 }
-                _exitElement(element, depth, startIndex);
+                _exitElement(element, depth, std::min(startIndex, [_attrStr length]));
             }
         }
     } else if (node.nodeType() == Node::TEXT_NODE)
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to