Title: [282209] trunk
Revision
282209
Author
[email protected]
Date
2021-09-09 04:38:34 -0700 (Thu, 09 Sep 2021)

Log Message

Chromium test-case asserts with ASSERTION FAILED: propertyMissingOrEqualToNone
https://bugs.webkit.org/show_bug.cgi?id=202904

Patch by Frederic Wang <[email protected]> on 2021-09-09
Reviewed by Darin Adler.

Source/WebCore:

WebCore::CompositeEditCommand::moveParagraphs calls createFragmentFromMarkup with a parameter
AnnotateForInterchange set to No. As a consequence, StyledMarkupAccumulator::serializeNodes
will not call EditingStyle::wrappingStyleForSerialization (in order to remove
-webkit-text-decorations-in-effect) contrary to the assumption of the ASSERT in
propertyMissingOrEqualToNone. This can lead to the ASSERT failing e.g. with the JustifyRight
command. This patch fixes that wrong expectation by importing the corresponding change and
test from Chromium [1].

[1] https://codereview.chromium.org/1522063002

Test: imported/blink/editing/execCommand/justify-right-in-effect-crash.html

* editing/markup.cpp:
(WebCore::StyledMarkupAccumulator::appendStyleNodeOpenTag): Skip the assert if we should not
annotate and update the code comment accordingly.

LayoutTests:

Import regression test from Blink.

* imported/blink/editing/execCommand/justify-right-in-effect-crash-expected.txt: Added.
* imported/blink/editing/execCommand/justify-right-in-effect-crash.html: Added.

Modified Paths

Added Paths

Diff

Modified: trunk/LayoutTests/ChangeLog (282208 => 282209)


--- trunk/LayoutTests/ChangeLog	2021-09-09 11:26:30 UTC (rev 282208)
+++ trunk/LayoutTests/ChangeLog	2021-09-09 11:38:34 UTC (rev 282209)
@@ -1,3 +1,15 @@
+2021-09-09  Frederic Wang  <[email protected]>
+
+        Chromium test-case asserts with ASSERTION FAILED: propertyMissingOrEqualToNone
+        https://bugs.webkit.org/show_bug.cgi?id=202904
+
+        Reviewed by Darin Adler.
+
+        Import regression test from Blink.
+
+        * imported/blink/editing/execCommand/justify-right-in-effect-crash-expected.txt: Added.
+        * imported/blink/editing/execCommand/justify-right-in-effect-crash.html: Added.
+
 2021-09-09  Manuel Rego Casasnovas  <[email protected]>
 
         [css-text-decor] Update WPT test suite

Added: trunk/LayoutTests/imported/blink/editing/execCommand/justify-right-in-effect-crash-expected.txt (0 => 282209)


--- trunk/LayoutTests/imported/blink/editing/execCommand/justify-right-in-effect-crash-expected.txt	                        (rev 0)
+++ trunk/LayoutTests/imported/blink/editing/execCommand/justify-right-in-effect-crash-expected.txt	2021-09-09 11:38:34 UTC (rev 282209)
@@ -0,0 +1 @@
+PASS if Blink doesn't crash.

Added: trunk/LayoutTests/imported/blink/editing/execCommand/justify-right-in-effect-crash.html (0 => 282209)


--- trunk/LayoutTests/imported/blink/editing/execCommand/justify-right-in-effect-crash.html	                        (rev 0)
+++ trunk/LayoutTests/imported/blink/editing/execCommand/justify-right-in-effect-crash.html	2021-09-09 11:38:34 UTC (rev 282209)
@@ -0,0 +1,24 @@
+<!DOCTYPE html>
+<html>
+<head>
+<script>
+if (window.testRunner)
+    testRunner.dumpAsText();
+
+window._onload_= function() {
+    document.designMode = "on";
+    document.execCommand("SelectAll");
+    document.execCommand("JustifyRight");
+    document.body.textContent = 'PASS if Blink doesn\'t crash.';
+};
+</script>
+<style>
+.CLASS3 {
+    -webkit-text-decorations-in-effect:underline;
+}
+</style>
+<body class="CLASS3">
+nls
+<hr>
+</body>
+</html>

Modified: trunk/Source/WebCore/ChangeLog (282208 => 282209)


--- trunk/Source/WebCore/ChangeLog	2021-09-09 11:26:30 UTC (rev 282208)
+++ trunk/Source/WebCore/ChangeLog	2021-09-09 11:38:34 UTC (rev 282209)
@@ -1,3 +1,26 @@
+2021-09-09  Frederic Wang  <[email protected]>
+
+        Chromium test-case asserts with ASSERTION FAILED: propertyMissingOrEqualToNone
+        https://bugs.webkit.org/show_bug.cgi?id=202904
+
+        Reviewed by Darin Adler.
+
+        WebCore::CompositeEditCommand::moveParagraphs calls createFragmentFromMarkup with a parameter
+        AnnotateForInterchange set to No. As a consequence, StyledMarkupAccumulator::serializeNodes
+        will not call EditingStyle::wrappingStyleForSerialization (in order to remove
+        -webkit-text-decorations-in-effect) contrary to the assumption of the ASSERT in
+        propertyMissingOrEqualToNone. This can lead to the ASSERT failing e.g. with the JustifyRight
+        command. This patch fixes that wrong expectation by importing the corresponding change and
+        test from Chromium [1].
+
+        [1] https://codereview.chromium.org/1522063002
+
+        Test: imported/blink/editing/execCommand/justify-right-in-effect-crash.html
+
+        * editing/markup.cpp:
+        (WebCore::StyledMarkupAccumulator::appendStyleNodeOpenTag): Skip the assert if we should not
+        annotate and update the code comment accordingly.
+
 2021-09-09  Myles C. Maxfield  <[email protected]>
 
         FontFaceSet.has() needs to react to style changes

Modified: trunk/Source/WebCore/editing/markup.cpp (282208 => 282209)


--- trunk/Source/WebCore/editing/markup.cpp	2021-09-09 11:26:30 UTC (rev 282208)
+++ trunk/Source/WebCore/editing/markup.cpp	2021-09-09 11:38:34 UTC (rev 282209)
@@ -383,8 +383,8 @@
 
 void StyledMarkupAccumulator::appendStyleNodeOpenTag(StringBuilder& out, StyleProperties* style, Document& document, bool isBlock)
 {
-    // wrappingStyleForSerialization should have removed -webkit-text-decorations-in-effect
-    ASSERT(propertyMissingOrEqualToNone(style, CSSPropertyWebkitTextDecorationsInEffect));
+    // With AnnotateForInterchange::Yes, wrappingStyleForSerialization should have removed -webkit-text-decorations-in-effect
+    ASSERT(!shouldAnnotate() || propertyMissingOrEqualToNone(style, CSSPropertyWebkitTextDecorationsInEffect));
     if (isBlock)
         out.append("<div style=\"");
     else
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to