- Source/WebCore/ChangeLog +15 lines
Lines 1-3 Source/WebCore/ChangeLog_sec1
1
2015-10-02  Ryosuke Niwa  <rniwa@webkit.org>
2
3
        ShadowRoot with leading or trailing white space cause a crash
4
        https://bugs.webkit.org/show_bug.cgi?id=149782
5
6
        Reviewed by NOBODY (OOPS!).
7
8
        Fixed the crash by adding a null pointer check since a TextNode that appears as a direct child
9
        of a ShadowRoot doesn't have a parent element.
10
11
        Test: fast/shadow-dom/shadow-root-with-child-whitespace-text-crash.html
12
13
        * style/RenderTreePosition.cpp:
14
        (WebCore::RenderTreePosition::previousSiblingRenderer):
15
1
2015-10-02  Antti Koivisto  <antti@apple.com>
16
2015-10-02  Antti Koivisto  <antti@apple.com>
2
17
3
        Inserting a child to a slot assigned node doesn't trigger repaint
18
        Inserting a child to a slot assigned node doesn't trigger repaint
- Source/WebCore/style/RenderTreePosition.cpp -2 / +4 lines
Lines 62-69 RenderObject* RenderTreePosition::previo Source/WebCore/style/RenderTreePosition.cpp_sec1
62
        if (renderer && !RenderTreePosition::isRendererReparented(*renderer))
62
        if (renderer && !RenderTreePosition::isRendererReparented(*renderer))
63
            return renderer;
63
            return renderer;
64
    }
64
    }
65
    if (PseudoElement* before = textNode.parentElement()->beforePseudoElement())
65
    if (auto* parent = textNode.parentElement()) {
66
        return before->renderer();
66
        if (PseudoElement* before = parent->beforePseudoElement())
67
            return before->renderer();
68
    }
67
    return nullptr;
69
    return nullptr;
68
}
70
}
69
71
- LayoutTests/ChangeLog +12 lines
Lines 1-3 LayoutTests/ChangeLog_sec1
1
2015-10-02  Ryosuke Niwa  <rniwa@webkit.org>
2
3
        ShadowRoot with leading or trailing white space cause a crash
4
        https://bugs.webkit.org/show_bug.cgi?id=149782
5
6
        Reviewed by NOBODY (OOPS!).
7
8
        Added a regression test.
9
10
        * fast/shadow-dom/shadow-root-with-child-whitespace-text-crash-expected.txt: Added.
11
        * fast/shadow-dom/shadow-root-with-child-whitespace-text-crash.html: Added.
12
1
2015-10-02  Simon Fraser  <simon.fraser@apple.com>
13
2015-10-02  Simon Fraser  <simon.fraser@apple.com>
2
14
3
        New baselines for some compositing tests.
15
        New baselines for some compositing tests.
- LayoutTests/fast/shadow-dom/shadow-root-with-child-whitespace-text-crash-expected.txt +3 lines
Line 0 LayoutTests/fast/shadow-dom/shadow-root-with-child-whitespace-text-crash-expected.txt_sec1
1
This tests creating a shadow root with leading and trailing white spaces. WebKit should not crash. You should see PASS below.
2
3
PASS
- LayoutTests/fast/shadow-dom/shadow-root-with-child-whitespace-text-crash.html +17 lines
Line 0 LayoutTests/fast/shadow-dom/shadow-root-with-child-whitespace-text-crash.html_sec1
1
<!DOCTYPE html>
2
<html>
3
<body>
4
<p>
5
This tests creating a shadow root with leading and trailing white spaces.
6
WebKit should not crash. You should see PASS below.
7
</p>
8
<div id="host">PASS</div>
9
<script>
10
if (window.testRunner)
11
    testRunner.dumpAsText();
12
13
var host = document.getElementById('host');
14
host.attachShadow({mode: 'closed'}).innerHTML = ` <slot></slot> `;
15
</script>
16
</body>
17
</html>

Return to Bug 149782