Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: ce41a20021a15862278d4b43e88bfe0f70d0a9b2
      
https://github.com/WebKit/WebKit/commit/ce41a20021a15862278d4b43e88bfe0f70d0a9b2
  Author: Alan Baradlay <[email protected]>
  Date:   2026-09-24 (Thu, 24 Sep 2026)

  Changed paths:
    A 
LayoutTests/fast/forms/input-placeholder-moves-without-layout-crash-expected.txt
    A LayoutTests/fast/forms/input-placeholder-moves-without-layout-crash.html
    M Source/WebCore/rendering/RenderTextControlSingleLine.cpp

  Log Message:
  -----------
  REGRESSION(317859@main): [ iOS ] 4x fast/* tests crash with ASSERTION FAILED: 
mode == Verify => !geometryChanged in RenderLayer::updateLayerPosition (CRASH)
https://bugs.webkit.org/show_bug.cgi?id=325012
<rdar://problem/188216588>

Reviewed by Simon Fraser.

The placeholder's layer should move along with the placeholder. Instead it 
keeps its old position and the layer position verification assert fires.

Normally after laying out a renderer, we mark its layer "dirty" by calling 
setSelfAndChildrenNeedPositionUpdate from RenderObject::clearNeedsLayout.
However a placeholder inside RenderTextControlSingleLine may move even when the 
placeholder itself is not dirty.
This change ensures that the associated layer is marked, even when the 
placeholder's layout is not called.

* 
LayoutTests/fast/forms/input-placeholder-moves-without-layout-crash-expected.txt:
 Added.
* LayoutTests/fast/forms/input-placeholder-moves-without-layout-crash.html: 
Added.
* Source/WebCore/rendering/RenderTextControlSingleLine.cpp:
(WebCore::RenderTextControlSingleLine::layout):

Canonical link: https://commits.webkit.org/321784@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to