Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: ce41a20021a15862278d4b43e88bfe0f70d0a9b2
https://github.com/WebKit/WebKit/commit/ce41a20021a15862278d4b43e88bfe0f70d0a9b2
Author: Alan Baradlay <[email protected]>
Date: 2026-09-24 (Thu, 24 Sep 2026)
Changed paths:
A
LayoutTests/fast/forms/input-placeholder-moves-without-layout-crash-expected.txt
A LayoutTests/fast/forms/input-placeholder-moves-without-layout-crash.html
M Source/WebCore/rendering/RenderTextControlSingleLine.cpp
Log Message:
-----------
REGRESSION(317859@main): [ iOS ] 4x fast/* tests crash with ASSERTION FAILED:
mode == Verify => !geometryChanged in RenderLayer::updateLayerPosition (CRASH)
https://bugs.webkit.org/show_bug.cgi?id=325012
<rdar://problem/188216588>
Reviewed by Simon Fraser.
The placeholder's layer should move along with the placeholder. Instead it
keeps its old position and the layer position verification assert fires.
Normally after laying out a renderer, we mark its layer "dirty" by calling
setSelfAndChildrenNeedPositionUpdate from RenderObject::clearNeedsLayout.
However a placeholder inside RenderTextControlSingleLine may move even when the
placeholder itself is not dirty.
This change ensures that the associated layer is marked, even when the
placeholder's layout is not called.
*
LayoutTests/fast/forms/input-placeholder-moves-without-layout-crash-expected.txt:
Added.
* LayoutTests/fast/forms/input-placeholder-moves-without-layout-crash.html:
Added.
* Source/WebCore/rendering/RenderTextControlSingleLine.cpp:
(WebCore::RenderTextControlSingleLine::layout):
Canonical link: https://commits.webkit.org/321784@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications