<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>105372</bug_id>
          
          <creation_ts>2012-12-18 17:40:11 -0800</creation_ts>
          <short_desc>accessibility/svg-bounds.html asserts</short_desc>
          <delta_ts>2012-12-20 10:45:29 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Accessibility</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://build.webkit.org/results/Apple%20MountainLion%20Debug%20WK1%20(Tests)/r138081%20(3961)/accessibility/svg-bounds-crash-log.txt</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Simon Fraser (smfr)">simon.fraser</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>cfleizach</cc>
    
    <cc>dmazzoni</cc>
    
    <cc>simon.fraser</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>794215</commentid>
    <comment_count>0</comment_count>
    <who name="Simon Fraser (smfr)">simon.fraser</who>
    <bug_when>2012-12-18 17:40:11 -0800</bug_when>
    <thetext>Process:         DumpRenderTree [47695]
Path:            /Volumes/VOLUME/*/DumpRenderTree
Identifier:      DumpRenderTree
Version:         0
Code Type:       X86-64 (Native)
Parent Process:  Python [46425]
User ID:         501

Date/Time:       2012-12-18 17:16:18.713 -0800
OS Version:      Mac OS X 10.8.2 (12C54)
Report Version:  10

Crashed Thread:  0  Dispatch queue: com.apple.main-thread

Exception Type:  EXC_BAD_ACCESS (SIGSEGV)
Exception Codes: KERN_INVALID_ADDRESS at 0x00000000bbadbeef

VM Regions Near 0xbbadbeef:
--&gt; 
    __TEXT                 00000001015fc000-0000000101698000 [  624K] r-x/rwx SM=COW  /Volumes/VOLUME/*

Application Specific Information:
CRASHING TEST: accessibility/svg-bounds.html

Thread 0 Crashed:: Dispatch queue: com.apple.main-thread
0   com.apple.WebCore             	0x00000001043f941e WebCore::RenderSVGRoot::mapLocalToContainer(WebCore::RenderLayerModelObject const*, WebCore::TransformState&amp;, unsigned int, bool*) const + 190 (RenderSVGRoot.cpp:407)
1   com.apple.WebCore             	0x000000010438e77e WebCore::RenderObject::localToAbsolute(WebCore::FloatPoint const&amp;, unsigned int) const + 110 (RenderObject.cpp:2052)
2   com.apple.WebCore             	0x000000010438e825 WebCore::RenderObject::absoluteFocusRingQuads(WTF::Vector&lt;WebCore::FloatQuad, 0ul&gt;&amp;) + 101 (RenderObject.cpp:1217)
3   com.apple.WebCore             	0x0000000102f3fd3c WebCore::AccessibilityRenderObject::boundingBoxRect() const + 284 (AccessibilityRenderObject.cpp:792)
4   com.apple.WebCore             	0x0000000102f4001d WebCore::AccessibilityRenderObject::elementRect() const + 93 (AccessibilityRenderObject.cpp:830)
5   com.apple.WebCore             	0x0000000102f3819e WebCore::AccessibilityObject::clickPoint() + 46 (AccessibilityObject.cpp:512)
6   com.apple.WebCore             	0x0000000102f40104 WebCore::AccessibilityRenderObject::clickPoint() + 212 (AccessibilityRenderObject.cpp:840)
7   com.apple.WebCore             	0x00000001048f9fc6 -[WebAccessibilityObjectWrapper accessibilityAttributeValue:] + 21126 (WebAccessibilityObjectWrapper.mm:2642)
8   DumpRenderTree                	0x0000000101607d56 AccessibilityUIElement::clickPointX() + 38 (AccessibilityUIElementMac.mm:602)
9   DumpRenderTree                	0x00000001015ff9b4 getClickPointXCallback(OpaqueJSContext const*, OpaqueJSValue*, OpaqueJSString*, OpaqueJSValue const**) + 52 (AccessibilityUIElement.cpp:765)
10  com.apple.JavaScriptCore      	0x0000000101b0c0e6 JSC::JSCallbackObject&lt;JSC::JSDestructibleObject&gt;::getStaticValue(JSC::ExecState*, JSC::PropertyName) + 406 (JSCallbackObjectFunctions.h:535)
11  com.apple.JavaScriptCore      	0x0000000101b02fbd JSC::JSCallbackObject&lt;JSC::JSDestructibleObject&gt;::getOwnPropertySlot(JSC::JSCell*, JSC::ExecState*, JSC::PropertyName, JSC::PropertySlot&amp;) + 1069 (JSCallbackObjectFunctions.h:165)
12  com.apple.JavaScriptCore      	0x00000001018b7ea6 JSC::JSCell::fastGetOwnPropertySlot(JSC::ExecState*, JSC::PropertyName, JSC::PropertySlot&amp;) + 150 (JSObject.h:1222)
13  com.apple.JavaScriptCore      	0x00000001018cba4c JSC::JSValue::get(JSC::ExecState*, JSC::PropertyName, JSC::PropertySlot&amp;) const + 204 (JSObject.h:1482)
14  com.apple.JavaScriptCore      	0x0000000101ca06b1 llint_slow_path_get_by_id + 241 (LLIntSlowPaths.cpp:915)
15  com.apple.JavaScriptCore      	0x0000000101ca9ad4 llint_op_get_by_id + 122
16  com.apple.JavaScriptCore      	0x0000000101aa4be4 JSC::JITCode::execute(JSC::JSStack*, JSC::ExecState*, JSC::JSGlobalData*) + 84 (JITCode.h:134)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>794233</commentid>
    <comment_count>1</comment_count>
    <who name="Simon Fraser (smfr)">simon.fraser</who>
    <bug_when>2012-12-18 18:04:21 -0800</bug_when>
    <thetext>Skipped in Debug in http://trac.webkit.org/changeset/138094</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>795559</commentid>
    <comment_count>2</comment_count>
    <who name="Dominic Mazzoni">dmazzoni</who>
    <bug_when>2012-12-20 10:45:29 -0800</bug_when>
    <thetext>http://trac.webkit.org/changeset/138272</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>