Title: [179706] trunk
- Revision
- 179706
- Author
- [email protected]
- Date
- 2015-02-05 13:55:45 -0800 (Thu, 05 Feb 2015)
Log Message
Crash due to failing to dirty a removed text node's line box
https://bugs.webkit.org/show_bug.cgi?id=136544
Reviewed by David Hyatt.
Source/WebCore:
Test: fast/text/remove-text-node-linebox-not-dirty-crash.html
* rendering/RenderLineBoxList.cpp:
(WebCore::RenderLineBoxList::dirtyLinesFromChangedChild): Make the check for dirtying the next
line box a bit more inclusive to avoid a case of a line box for a destroyed render object not
being dirtied. In particular, when the text node's parent has no line boxes but contains BRs.
LayoutTests:
* fast/text/remove-text-node-linebox-not-dirty-crash-expected.txt: Added.
* fast/text/remove-text-node-linebox-not-dirty-crash.html: Added.
Modified Paths
Added Paths
Diff
Modified: trunk/LayoutTests/ChangeLog (179705 => 179706)
--- trunk/LayoutTests/ChangeLog 2015-02-05 21:52:11 UTC (rev 179705)
+++ trunk/LayoutTests/ChangeLog 2015-02-05 21:55:45 UTC (rev 179706)
@@ -1,3 +1,13 @@
+2015-02-05 Maciej Stachowiak <[email protected]>
+
+ Crash due to failing to dirty a removed text node's line box
+ https://bugs.webkit.org/show_bug.cgi?id=136544
+
+ Reviewed by David Hyatt.
+
+ * fast/text/remove-text-node-linebox-not-dirty-crash-expected.txt: Added.
+ * fast/text/remove-text-node-linebox-not-dirty-crash.html: Added.
+
2015-02-05 Brent Fulgham <[email protected]>
[Win] Mark another group of assertion failures.
Added: trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash-expected.txt (0 => 179706)
--- trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash-expected.txt (rev 0)
+++ trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash-expected.txt 2015-02-05 21:55:45 UTC (rev 179706)
@@ -0,0 +1,3 @@
+This test passes if it does not crash. bar
+
+
Added: trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash.html (0 => 179706)
--- trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash.html (rev 0)
+++ trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash.html 2015-02-05 21:55:45 UTC (rev 179706)
@@ -0,0 +1,23 @@
+<script>
+if (window.testRunner) {
+ testRunner.dumpAsText();
+ testRunner.waitUntilDone();
+}
+
+window._onload_ = function()
+{
+ document.body.offsetTop;
+ b.lastChild.parentNode.removeChild(b.lastChild);
+ document.body.offsetTop;
+ a.firstChild.parentNode.removeChild(a.firstChild);
+ document.body.offsetTop;
+ if (window.testRunner)
+ testRunner.notifyDone();
+}
+</script>
+<div id="a">foo</div>
+<div></div>
+ This test passes if it does not crash. <output>
+<unknown>bar</output>
+<span id="b">
+<span><div style="display:inline-block"></div><br><br></span>
Modified: trunk/Source/WebCore/ChangeLog (179705 => 179706)
--- trunk/Source/WebCore/ChangeLog 2015-02-05 21:52:11 UTC (rev 179705)
+++ trunk/Source/WebCore/ChangeLog 2015-02-05 21:55:45 UTC (rev 179706)
@@ -1,3 +1,17 @@
+2015-02-05 Maciej Stachowiak <[email protected]>
+
+ Crash due to failing to dirty a removed text node's line box
+ https://bugs.webkit.org/show_bug.cgi?id=136544
+
+ Reviewed by David Hyatt.
+
+ Test: fast/text/remove-text-node-linebox-not-dirty-crash.html
+
+ * rendering/RenderLineBoxList.cpp:
+ (WebCore::RenderLineBoxList::dirtyLinesFromChangedChild): Make the check for dirtying the next
+ line box a bit more inclusive to avoid a case of a line box for a destroyed render object not
+ being dirtied. In particular, when the text node's parent has no line boxes but contains BRs.
+
2015-02-05 Chris Dumez <[email protected]>
Free memory read under MemoryCache::pruneLiveResourcesToSize()
Modified: trunk/Source/WebCore/rendering/RenderLineBoxList.cpp (179705 => 179706)
--- trunk/Source/WebCore/rendering/RenderLineBoxList.cpp 2015-02-05 21:52:11 UTC (rev 179705)
+++ trunk/Source/WebCore/rendering/RenderLineBoxList.cpp 2015-02-05 21:55:45 UTC (rev 179706)
@@ -396,7 +396,7 @@
// space, the search for |child|'s linebox will go past the leading space to the previous linebox and select that
// one as |box|. If we hit that situation here, dirty the |box| actually containing the child too.
bool insertedAfterLeadingSpace = box->lineBreakObj() == child.previousSibling();
- if (adjacentBox && (adjacentBox->lineBreakObj() == &child || child.isBR() || (current && current->isBR())
+ if (adjacentBox && (adjacentBox->lineBreakObj()->isDescendantOf(&child) || child.isBR() || (current && current->isBR())
|| insertedAfterLeadingSpace || isIsolated(container.style().unicodeBidi())))
adjacentBox->markDirty();
}
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes