Title: [293725] trunk
Revision
293725
Author
[email protected]
Date
2022-05-03 08:45:26 -0700 (Tue, 03 May 2022)

Log Message

[CSS Cascade Layers] Endless recursion with revert-layer in other tree context
https://bugs.webkit.org/show_bug.cgi?id=239967
<rdar://92449950>

Reviewed by Alan Bujtas.

Source/WebCore:

We should only revert within a tree context (scope).

Adding more comprehensive WPTs separately.

Test: fast/css/revert-layer-tree-context-stack-overflow.html

* style/PropertyCascade.cpp:
(WebCore::Style::PropertyCascade::PropertyCascade):

Pass the property tree scope to the rollback cascade.

(WebCore::Style::PropertyCascade::addMatch):

Don't include properties from lower priority tree scopes to rollback cascade.
Reverse the logic for clarity.

* style/PropertyCascade.h:
(WebCore::Style::PropertyCascade::PropertyCascade):
* style/StyleBuilder.cpp:
(WebCore::Style::Builder::ensureRollbackCascadeForRevert):
(WebCore::Style::Builder::ensureRollbackCascadeForRevertLayer):
(WebCore::Style::Builder::makeRollbackCascadeKey):

Include tree scope to the key.

* style/StyleBuilder.h:

LayoutTests:

* fast/css/revert-layer-tree-context-stack-overflow-expected.html: Added.
* fast/css/revert-layer-tree-context-stack-overflow.html: Added.

Modified Paths

Added Paths

Diff

Modified: trunk/LayoutTests/ChangeLog (293724 => 293725)


--- trunk/LayoutTests/ChangeLog	2022-05-03 14:31:34 UTC (rev 293724)
+++ trunk/LayoutTests/ChangeLog	2022-05-03 15:45:26 UTC (rev 293725)
@@ -1,3 +1,14 @@
+2022-05-03  Antti Koivisto  <[email protected]>
+
+        [CSS Cascade Layers] Endless recursion with revert-layer in other tree context
+        https://bugs.webkit.org/show_bug.cgi?id=239967
+        <rdar://92449950>
+
+        Reviewed by Alan Bujtas.
+
+        * fast/css/revert-layer-tree-context-stack-overflow-expected.html: Added.
+        * fast/css/revert-layer-tree-context-stack-overflow.html: Added.
+
 2022-05-03  Kimmo Kinnunen  <[email protected]>
 
         IPC stream connection sends should fail immediately when connection closes

Added: trunk/LayoutTests/fast/css/revert-layer-tree-context-stack-overflow-expected.html (0 => 293725)


--- trunk/LayoutTests/fast/css/revert-layer-tree-context-stack-overflow-expected.html	                        (rev 0)
+++ trunk/LayoutTests/fast/css/revert-layer-tree-context-stack-overflow-expected.html	2022-05-03 15:45:26 UTC (rev 293725)
@@ -0,0 +1 @@
+<input placeholder="a">

Added: trunk/LayoutTests/fast/css/revert-layer-tree-context-stack-overflow.html (0 => 293725)


--- trunk/LayoutTests/fast/css/revert-layer-tree-context-stack-overflow.html	                        (rev 0)
+++ trunk/LayoutTests/fast/css/revert-layer-tree-context-stack-overflow.html	2022-05-03 15:45:26 UTC (rev 293725)
@@ -0,0 +1,6 @@
+<style>
+  ::-webkit-input-placeholder {
+    display: revert-layer;
+  }
+</style>
+<input placeholder="a">

Modified: trunk/Source/WebCore/ChangeLog (293724 => 293725)


--- trunk/Source/WebCore/ChangeLog	2022-05-03 14:31:34 UTC (rev 293724)
+++ trunk/Source/WebCore/ChangeLog	2022-05-03 15:45:26 UTC (rev 293725)
@@ -1,3 +1,38 @@
+2022-05-03  Antti Koivisto  <[email protected]>
+
+        [CSS Cascade Layers] Endless recursion with revert-layer in other tree context
+        https://bugs.webkit.org/show_bug.cgi?id=239967
+        <rdar://92449950>
+
+        Reviewed by Alan Bujtas.
+
+        We should only revert within a tree context (scope).
+
+        Adding more comprehensive WPTs separately.
+
+        Test: fast/css/revert-layer-tree-context-stack-overflow.html
+
+        * style/PropertyCascade.cpp:
+        (WebCore::Style::PropertyCascade::PropertyCascade):
+
+        Pass the property tree scope to the rollback cascade.
+
+        (WebCore::Style::PropertyCascade::addMatch):
+
+        Don't include properties from lower priority tree scopes to rollback cascade.
+        Reverse the logic for clarity.
+
+        * style/PropertyCascade.h:
+        (WebCore::Style::PropertyCascade::PropertyCascade):
+        * style/StyleBuilder.cpp:
+        (WebCore::Style::Builder::ensureRollbackCascadeForRevert):
+        (WebCore::Style::Builder::ensureRollbackCascadeForRevertLayer):
+        (WebCore::Style::Builder::makeRollbackCascadeKey):
+
+        Include tree scope to the key.
+
+        * style/StyleBuilder.h:
+
 2022-05-03  Youenn Fablet  <[email protected]>
 
         ServiceWorkerRegistration update should fail if called from an installing service worker context

Modified: trunk/Source/WebCore/style/PropertyCascade.cpp (293724 => 293725)


--- trunk/Source/WebCore/style/PropertyCascade.cpp	2022-05-03 14:31:34 UTC (rev 293724)
+++ trunk/Source/WebCore/style/PropertyCascade.cpp	2022-05-03 15:45:26 UTC (rev 293725)
@@ -46,10 +46,11 @@
     buildCascade();
 }
 
-PropertyCascade::PropertyCascade(const PropertyCascade& parent, CascadeLevel maximumCascadeLevel, std::optional<CascadeLayerPriority> maximumCascadeLayerPriorityForRollback)
+PropertyCascade::PropertyCascade(const PropertyCascade& parent, CascadeLevel maximumCascadeLevel, std::optional<ScopeOrdinal> rollbackScope, std::optional<CascadeLayerPriority> maximumCascadeLayerPriorityForRollback)
     : m_matchResult(parent.m_matchResult)
     , m_includedProperties(parent.m_includedProperties)
     , m_maximumCascadeLevel(maximumCascadeLevel)
+    , m_rollbackScope(rollbackScope)
     , m_maximumCascadeLayerPriorityForRollback(maximumCascadeLayerPriorityForRollback)
 {
     buildCascade();
@@ -172,18 +173,16 @@
 
 bool PropertyCascade::addMatch(const MatchedProperties& matchedProperties, CascadeLevel cascadeLevel, bool important)
 {
-    auto skipForRollback = [&] {
-        if (!m_maximumCascadeLayerPriorityForRollback)
-            return false;
-        if (matchedProperties.styleScopeOrdinal != ScopeOrdinal::Element)
-            return false;
+    auto includePropertiesForRollback = [&] {
+        if (m_rollbackScope && matchedProperties.styleScopeOrdinal > *m_rollbackScope)
+            return true;
         if (cascadeLevel < m_maximumCascadeLevel)
+            return true;
+        if (matchedProperties.fromStyleAttribute == FromStyleAttribute::Yes)
             return false;
-        if (matchedProperties.fromStyleAttribute == FromStyleAttribute::Yes)
-            return true;
-        return matchedProperties.cascadeLayerPriority > *m_maximumCascadeLayerPriorityForRollback;
+        return matchedProperties.cascadeLayerPriority <= *m_maximumCascadeLayerPriorityForRollback;
     };
-    if (skipForRollback())
+    if (m_maximumCascadeLayerPriorityForRollback && !includePropertiesForRollback())
         return false;
 
     auto& styleProperties = *matchedProperties.properties;

Modified: trunk/Source/WebCore/style/PropertyCascade.h (293724 => 293725)


--- trunk/Source/WebCore/style/PropertyCascade.h	2022-05-03 14:31:34 UTC (rev 293724)
+++ trunk/Source/WebCore/style/PropertyCascade.h	2022-05-03 15:45:26 UTC (rev 293725)
@@ -41,7 +41,7 @@
     enum IncludedProperties { All, InheritedOnly };
 
     PropertyCascade(const MatchResult&, CascadeLevel, IncludedProperties);
-    PropertyCascade(const PropertyCascade&, CascadeLevel, std::optional<CascadeLayerPriority> maximumCascadeLayerPriorityForRollback = { });
+    PropertyCascade(const PropertyCascade&, CascadeLevel, std::optional<ScopeOrdinal> rollbackScope = { }, std::optional<CascadeLayerPriority> maximumCascadeLayerPriorityForRollback = { });
 
     ~PropertyCascade();
 
@@ -85,6 +85,7 @@
     const MatchResult& m_matchResult;
     const IncludedProperties m_includedProperties;
     const CascadeLevel m_maximumCascadeLevel;
+    const std::optional<ScopeOrdinal> m_rollbackScope;
     const std::optional<CascadeLayerPriority> m_maximumCascadeLayerPriorityForRollback;
 
     // The CSSPropertyID enum is sorted like this:

Modified: trunk/Source/WebCore/style/StyleBuilder.cpp (293724 => 293725)


--- trunk/Source/WebCore/style/StyleBuilder.cpp	2022-05-03 14:31:34 UTC (rev 293724)
+++ trunk/Source/WebCore/style/StyleBuilder.cpp	2022-05-03 15:45:26 UTC (rev 293725)
@@ -388,7 +388,7 @@
 
     --rollbackCascadeLevel;
 
-    auto key = makeRollbackCascadeKey(rollbackCascadeLevel, 0);
+    auto key = makeRollbackCascadeKey(rollbackCascadeLevel);
     return m_rollbackCascades.ensure(key, [&] {
         return makeUnique<const PropertyCascade>(m_cascade, rollbackCascadeLevel);
     }).iterator->value.get();
@@ -407,15 +407,15 @@
     if (property.fromStyleAttribute == FromStyleAttribute::No)
         --rollbackLayerPriority;
 
-    auto key = makeRollbackCascadeKey(property.cascadeLevel, rollbackLayerPriority);
+    auto key = makeRollbackCascadeKey(property.cascadeLevel, property.styleScopeOrdinal, rollbackLayerPriority);
     return m_rollbackCascades.ensure(key, [&] {
-        return makeUnique<const PropertyCascade>(m_cascade, property.cascadeLevel, rollbackLayerPriority);
+        return makeUnique<const PropertyCascade>(m_cascade, property.cascadeLevel, property.styleScopeOrdinal, rollbackLayerPriority);
     }).iterator->value.get();
 }
 
-auto Builder::makeRollbackCascadeKey(CascadeLevel cascadeLevel, CascadeLayerPriority cascadeLayerPriority) -> RollbackCascadeKey
+auto Builder::makeRollbackCascadeKey(CascadeLevel cascadeLevel, ScopeOrdinal scopeOrdinal, CascadeLayerPriority cascadeLayerPriority) -> RollbackCascadeKey
 {
-    return { static_cast<unsigned>(cascadeLevel), static_cast<unsigned>(cascadeLayerPriority) };
+    return { static_cast<unsigned>(cascadeLevel), static_cast<unsigned>(scopeOrdinal), static_cast<unsigned>(cascadeLayerPriority) };
 }
 
 }

Modified: trunk/Source/WebCore/style/StyleBuilder.h (293724 => 293725)


--- trunk/Source/WebCore/style/StyleBuilder.h	2022-05-03 14:31:34 UTC (rev 293724)
+++ trunk/Source/WebCore/style/StyleBuilder.h	2022-05-03 15:45:26 UTC (rev 293725)
@@ -65,8 +65,8 @@
     const PropertyCascade* ensureRollbackCascadeForRevert();
     const PropertyCascade* ensureRollbackCascadeForRevertLayer();
 
-    using RollbackCascadeKey = std::pair<unsigned, unsigned>;
-    RollbackCascadeKey makeRollbackCascadeKey(CascadeLevel, CascadeLayerPriority);
+    using RollbackCascadeKey = std::tuple<unsigned, unsigned, unsigned>;
+    RollbackCascadeKey makeRollbackCascadeKey(CascadeLevel, ScopeOrdinal = ScopeOrdinal::Element, CascadeLayerPriority = 0);
 
     const PropertyCascade m_cascade;
     // Rollback cascades are build on demand to resolve 'revert' and 'revert-layer' keywords.
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to