Title: [179706] trunk
Revision
179706
Author
[email protected]
Date
2015-02-05 13:55:45 -0800 (Thu, 05 Feb 2015)

Log Message

Crash due to failing to dirty a removed text node's line box
https://bugs.webkit.org/show_bug.cgi?id=136544

Reviewed by David Hyatt.
Source/WebCore:

        
Test: fast/text/remove-text-node-linebox-not-dirty-crash.html

* rendering/RenderLineBoxList.cpp:
(WebCore::RenderLineBoxList::dirtyLinesFromChangedChild): Make the check for dirtying the next
line box a bit more inclusive to avoid a case of a line box for a destroyed render object not
being dirtied. In particular, when the text node's parent has no line boxes but contains BRs.

LayoutTests:


* fast/text/remove-text-node-linebox-not-dirty-crash-expected.txt: Added.
* fast/text/remove-text-node-linebox-not-dirty-crash.html: Added.

Modified Paths

Added Paths

Diff

Modified: trunk/LayoutTests/ChangeLog (179705 => 179706)


--- trunk/LayoutTests/ChangeLog	2015-02-05 21:52:11 UTC (rev 179705)
+++ trunk/LayoutTests/ChangeLog	2015-02-05 21:55:45 UTC (rev 179706)
@@ -1,3 +1,13 @@
+2015-02-05  Maciej Stachowiak  <[email protected]>
+
+        Crash due to failing to dirty a removed text node's line box
+        https://bugs.webkit.org/show_bug.cgi?id=136544
+
+        Reviewed by David Hyatt.
+
+        * fast/text/remove-text-node-linebox-not-dirty-crash-expected.txt: Added.
+        * fast/text/remove-text-node-linebox-not-dirty-crash.html: Added.
+
 2015-02-05  Brent Fulgham  <[email protected]>
 
         [Win] Mark another group of assertion failures.

Added: trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash-expected.txt (0 => 179706)


--- trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash-expected.txt	                        (rev 0)
+++ trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash-expected.txt	2015-02-05 21:55:45 UTC (rev 179706)
@@ -0,0 +1,3 @@
+This test passes if it does not crash.  bar
+
+

Added: trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash.html (0 => 179706)


--- trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash.html	                        (rev 0)
+++ trunk/LayoutTests/fast/text/remove-text-node-linebox-not-dirty-crash.html	2015-02-05 21:55:45 UTC (rev 179706)
@@ -0,0 +1,23 @@
+<script>
+if (window.testRunner) {
+    testRunner.dumpAsText();
+    testRunner.waitUntilDone();
+}
+
+window._onload_ = function()
+{
+    document.body.offsetTop;
+    b.lastChild.parentNode.removeChild(b.lastChild);
+    document.body.offsetTop;
+    a.firstChild.parentNode.removeChild(a.firstChild);
+    document.body.offsetTop;
+    if (window.testRunner)
+        testRunner.notifyDone();
+}
+</script>
+<div id="a">foo</div>
+<div></div>
+ This test passes if it does not crash. <output>
+<unknown>bar</output>
+<span id="b">
+<span><div style="display:inline-block"></div><br><br></span>

Modified: trunk/Source/WebCore/ChangeLog (179705 => 179706)


--- trunk/Source/WebCore/ChangeLog	2015-02-05 21:52:11 UTC (rev 179705)
+++ trunk/Source/WebCore/ChangeLog	2015-02-05 21:55:45 UTC (rev 179706)
@@ -1,3 +1,17 @@
+2015-02-05  Maciej Stachowiak  <[email protected]>
+
+        Crash due to failing to dirty a removed text node's line box
+        https://bugs.webkit.org/show_bug.cgi?id=136544
+
+        Reviewed by David Hyatt.
+        
+        Test: fast/text/remove-text-node-linebox-not-dirty-crash.html
+
+        * rendering/RenderLineBoxList.cpp:
+        (WebCore::RenderLineBoxList::dirtyLinesFromChangedChild): Make the check for dirtying the next
+        line box a bit more inclusive to avoid a case of a line box for a destroyed render object not
+        being dirtied. In particular, when the text node's parent has no line boxes but contains BRs.
+
 2015-02-05  Chris Dumez  <[email protected]>
 
         Free memory read under MemoryCache::pruneLiveResourcesToSize()

Modified: trunk/Source/WebCore/rendering/RenderLineBoxList.cpp (179705 => 179706)


--- trunk/Source/WebCore/rendering/RenderLineBoxList.cpp	2015-02-05 21:52:11 UTC (rev 179705)
+++ trunk/Source/WebCore/rendering/RenderLineBoxList.cpp	2015-02-05 21:55:45 UTC (rev 179706)
@@ -396,7 +396,7 @@
         // space, the search for |child|'s linebox will go past the leading space to the previous linebox and select that
         // one as |box|. If we hit that situation here, dirty the |box| actually containing the child too. 
         bool insertedAfterLeadingSpace = box->lineBreakObj() == child.previousSibling();
-        if (adjacentBox && (adjacentBox->lineBreakObj() == &child || child.isBR() || (current && current->isBR())
+        if (adjacentBox && (adjacentBox->lineBreakObj()->isDescendantOf(&child) || child.isBR() || (current && current->isBR())
             || insertedAfterLeadingSpace || isIsolated(container.style().unicodeBidi())))
             adjacentBox->markDirty();
     }
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to