| Differences between
and this patch
- a/LayoutTests/ChangeLog +10 lines
Lines 1-3 a/LayoutTests/ChangeLog_sec1
1
2020-03-31  Antti Koivisto  <antti@apple.com>
2
3
        Nullptr crash in InlineTextBox::emphasisMarkExistsAndIsAbove
4
        https://bugs.webkit.org/show_bug.cgi?id=207034
5
6
        Reviewed by Zalan Bujtas.
7
8
        * editing/selection/selection-update-during-anonymous-inline-teardown-expected.txt: Added.
9
        * editing/selection/selection-update-during-anonymous-inline-teardown.html: Added.
10
1
2020-03-30  Antti Koivisto  <antti@apple.com>
11
2020-03-30  Antti Koivisto  <antti@apple.com>
2
12
3
        Delete css-modsel-* tests under css3/ and fast/
13
        Delete css-modsel-* tests under css3/ and fast/
- a/LayoutTests/editing/selection/selection-update-during-anonymous-inline-teardown-expected.txt +2 lines
Line 0 a/LayoutTests/editing/selection/selection-update-during-anonymous-inline-teardown-expected.txt_sec1
1
This test passes if it doesn't crash
2
content
- a/LayoutTests/editing/selection/selection-update-during-anonymous-inline-teardown.html +15 lines
Line 0 a/LayoutTests/editing/selection/selection-update-during-anonymous-inline-teardown.html_sec1
1
<style>
2
span {
3
  -webkit-text-emphasis: open;
4
  display: contents;
5
}
6
svg { 
7
  border-left: 1px solid red; 
8
}
9
</style><svg><text>This test passes if it doesn't crash</text></svg><span>content</span><script>
10
if (window.testRunner)
11
    testRunner.dumpAsText();
12
document.body.offsetHeight;
13
document.execCommand("selectAll", false);
14
document.linkColor = "red";
15
</script>
- a/Source/WebCore/ChangeLog +16 lines
Lines 1-3 a/Source/WebCore/ChangeLog_sec1
1
2020-03-31  Antti Koivisto  <antti@apple.com>
2
3
        Nullptr crash in InlineTextBox::emphasisMarkExistsAndIsAbove
4
        https://bugs.webkit.org/show_bug.cgi?id=207034
5
6
        Reviewed by Zalan Bujtas.
7
8
        The repro case was fixed in https://bugs.webkit.org/show_bug.cgi?id=209695.
9
10
        Test: editing/selection/selection-update-during-anonymous-inline-teardown.html
11
12
        * rendering/InlineTextBox.cpp:
13
        (WebCore::InlineTextBox::emphasisMarkExistsAndIsAbove const):
14
15
        Also add a null check to be sure.
16
1
2020-03-30  Simon Fraser  <simon.fraser@apple.com>
17
2020-03-30  Simon Fraser  <simon.fraser@apple.com>
2
18
3
        Scroll latching state is not a stack
19
        Scroll latching state is not a stack
- a/Source/WebCore/rendering/InlineTextBox.cpp -1 / +1 lines
Lines 417-423 Optional<bool> InlineTextBox::emphasisMarkExistsAndIsAbove(const RenderStyle& st a/Source/WebCore/rendering/InlineTextBox.cpp_sec1
417
        return isAbove; // Ruby text is always over, so it cannot suppress emphasis marks under.
417
        return isAbove; // Ruby text is always over, so it cannot suppress emphasis marks under.
418
418
419
    RenderBlock* containingBlock = renderer().containingBlock();
419
    RenderBlock* containingBlock = renderer().containingBlock();
420
    if (!containingBlock->isRubyBase())
420
    if (!containingBlock || !containingBlock->isRubyBase())
421
        return isAbove; // This text is not inside a ruby base, so it does not have ruby text over it.
421
        return isAbove; // This text is not inside a ruby base, so it does not have ruby text over it.
422
422
423
    if (!is<RenderRubyRun>(*containingBlock->parent()))
423
    if (!is<RenderRubyRun>(*containingBlock->parent()))

Return to Bug 207034