Title: [282492] releases/WebKitGTK/webkit-2.32
- Revision
- 282492
- Author
- [email protected]
- Date
- 2021-09-16 00:35:49 -0700 (Thu, 16 Sep 2021)
Log Message
Merge r275320 - Null pointer access crash in WebCore::makeBoundaryPoint(..)
https://bugs.webkit.org/show_bug.cgi?id=223977
Patch by Venky Dass <[email protected]> on 2021-03-31
Reviewed by Darin Adler.
Source/WebCore:
In makeBoundaryPoint, position.containerNode() can be nullptr even if position.isNull() was false
Test: LayoutTests/editing/inserting/crash-make-boundary-point.html
* dom/Position.cpp:
(WebCore::makeBoundaryPoint):
LayoutTests:
Adding a refression test case.
* editing/inserting/crash-make-boundary-point-expected.txt: Added.
* editing/inserting/crash-make-boundary-point.html: Added.
Modified Paths
Added Paths
Diff
Modified: releases/WebKitGTK/webkit-2.32/LayoutTests/ChangeLog (282491 => 282492)
--- releases/WebKitGTK/webkit-2.32/LayoutTests/ChangeLog 2021-09-16 07:34:18 UTC (rev 282491)
+++ releases/WebKitGTK/webkit-2.32/LayoutTests/ChangeLog 2021-09-16 07:35:49 UTC (rev 282492)
@@ -1,3 +1,15 @@
+2021-03-31 Venky Dass <[email protected]>
+
+ Null pointer access crash in WebCore::makeBoundaryPoint(..)
+ https://bugs.webkit.org/show_bug.cgi?id=223977
+
+ Reviewed by Darin Adler.
+
+ Adding a refression test case.
+
+ * editing/inserting/crash-make-boundary-point-expected.txt: Added.
+ * editing/inserting/crash-make-boundary-point.html: Added.
+
2021-03-29 Chris Dumez <[email protected]>
REGRESSION(r274992): Nullptr crash in FontCache::retrieveOrAddCachedFonts
Added: releases/WebKitGTK/webkit-2.32/LayoutTests/editing/inserting/crash-make-boundary-point-expected.txt (0 => 282492)
--- releases/WebKitGTK/webkit-2.32/LayoutTests/editing/inserting/crash-make-boundary-point-expected.txt (rev 0)
+++ releases/WebKitGTK/webkit-2.32/LayoutTests/editing/inserting/crash-make-boundary-point-expected.txt 2021-09-16 07:35:49 UTC (rev 282492)
@@ -0,0 +1 @@
+PASS. WebKit did not crash.
Added: releases/WebKitGTK/webkit-2.32/LayoutTests/editing/inserting/crash-make-boundary-point.html (0 => 282492)
--- releases/WebKitGTK/webkit-2.32/LayoutTests/editing/inserting/crash-make-boundary-point.html (rev 0)
+++ releases/WebKitGTK/webkit-2.32/LayoutTests/editing/inserting/crash-make-boundary-point.html 2021-09-16 07:35:49 UTC (rev 282492)
@@ -0,0 +1,25 @@
+<!DOCTYPE html>
+<html>
+<head>
+<style>
+ style, script, head {
+ display: block;
+ }
+</style>
+<script>
+function runTest()
+{
+ document.documentElement.appendChild(document.createElement('input'));
+ document.execCommand('SelectAll');
+ document.designMode = 'on';
+ document.execCommand('JustifyRight');
+ document.execCommand('FormatBlock', false, 'div');
+ if (window.testRunner)
+ testRunner.dumpAsText();
+ document.documentElement.textContent = 'PASS. WebKit did not crash.';
+}
+window._onload_ = runTest;
+</script>
+</head>
+<body></body>
+</html>
Modified: releases/WebKitGTK/webkit-2.32/Source/WebCore/ChangeLog (282491 => 282492)
--- releases/WebKitGTK/webkit-2.32/Source/WebCore/ChangeLog 2021-09-16 07:34:18 UTC (rev 282491)
+++ releases/WebKitGTK/webkit-2.32/Source/WebCore/ChangeLog 2021-09-16 07:35:49 UTC (rev 282492)
@@ -1,3 +1,17 @@
+2021-03-31 Venky Dass <[email protected]>
+
+ Null pointer access crash in WebCore::makeBoundaryPoint(..)
+ https://bugs.webkit.org/show_bug.cgi?id=223977
+
+ Reviewed by Darin Adler.
+
+ In makeBoundaryPoint, position.containerNode() can be nullptr even if position.isNull() was false
+
+ Test: LayoutTests/editing/inserting/crash-make-boundary-point.html
+
+ * dom/Position.cpp:
+ (WebCore::makeBoundaryPoint):
+
2021-08-21 Sihui Liu <[email protected]>
IndexedDB: crash when triggering IDBOpenRequest completion back on a worker thread
Modified: releases/WebKitGTK/webkit-2.32/Source/WebCore/dom/Position.cpp (282491 => 282492)
--- releases/WebKitGTK/webkit-2.32/Source/WebCore/dom/Position.cpp 2021-09-16 07:34:18 UTC (rev 282491)
+++ releases/WebKitGTK/webkit-2.32/Source/WebCore/dom/Position.cpp 2021-09-16 07:35:49 UTC (rev 282492)
@@ -1594,9 +1594,10 @@
Optional<BoundaryPoint> makeBoundaryPoint(const Position& position)
{
- if (position.isNull())
+ auto container = makeRefPtr(position.containerNode());
+ if (!container)
return WTF::nullopt;
- return BoundaryPoint { *position.containerNode(), static_cast<unsigned>(position.computeOffsetInContainerNode()) };
+ return BoundaryPoint { container.releaseNonNull(), static_cast<unsigned>(position.computeOffsetInContainerNode()) };
}
PartialOrdering documentOrder(const Position& a, const Position& b)
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes