<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>108084</bug_id>
          
          <creation_ts>2013-01-28 08:16:49 -0800</creation_ts>
          <short_desc>Crash inside RenderBlock::layoutRunsAndFloatsInRange in the widow code</short_desc>
          <delta_ts>2013-01-28 14:29:55 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Layout and Rendering</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Julien Chaffraix">jchaffraix</reporter>
          <assigned_to name="Julien Chaffraix">jchaffraix</assigned_to>
          <cc>darin</cc>
    
    <cc>dino</cc>
    
    <cc>eric</cc>
    
    <cc>ojan.autocc</cc>
    
    <cc>webkit.review.bot</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>817764</commentid>
    <comment_count>0</comment_count>
    <who name="Julien Chaffraix">jchaffraix</who>
    <bug_when>2013-01-28 08:16:49 -0800</bug_when>
    <thetext>We are getting bug reports for a crasher in the widow code. I tried several times to see if I could get a reproduction but unfortunately couldn&apos;t.

Here is the code involved (line 1663 in RenderBlockLineLayout.cpp):

int numLinesHanging = 1;
while (lineBox &amp;&amp; lineBox != firstLineInBlock &amp;&amp; !lineBox-&gt;isFirstAfterPageBreak()) {
    ...
}

// If there were no breaks in the block, we didn&apos;t create any widows.
if (!lineBox-&gt;isFirstAfterPageBreak() || lineBox == firstLineInBlock)
    return;

The crash is a NULL dereference that happens in the &apos;if&apos;. The &apos;while&apos; NULL-checks |lineBox| but the following &apos;if&apos; doesn&apos;t, which makes me think that this is the bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>817778</commentid>
    <comment_count>1</comment_count>
      <attachid>184991</attachid>
    <who name="Julien Chaffraix">jchaffraix</who>
    <bug_when>2013-01-28 08:41:56 -0800</bug_when>
    <thetext>Created attachment 184991
Proposed blind fix.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>818107</commentid>
    <comment_count>2</comment_count>
      <attachid>184991</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2013-01-28 14:29:52 -0800</bug_when>
    <thetext>Comment on attachment 184991
Proposed blind fix.

Clearing flags on attachment: 184991

Committed r141009: &lt;http://trac.webkit.org/changeset/141009&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>818108</commentid>
    <comment_count>3</comment_count>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2013-01-28 14:29:55 -0800</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>184991</attachid>
            <date>2013-01-28 08:41:56 -0800</date>
            <delta_ts>2013-01-28 14:29:52 -0800</delta_ts>
            <desc>Proposed blind fix.</desc>
            <filename>bug-108084-20130128083843.patch</filename>
            <type>text/plain</type>
            <size>1800</size>
            <attacher name="Julien Chaffraix">jchaffraix</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTQwOTY3CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggZTY1ZWFmODBjMmNlMGYy
OWMxZjY3NjRiYTg1MjgzNmEwZWQyZmNlMy4uNDFlNTlhODg5NDY5YzQxYWQ3ZDUzY2ZjMWNhYjUy
YTM3M2MzNWI4MSAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDE5IEBACisyMDEzLTAxLTI4ICBKdWxp
ZW4gQ2hhZmZyYWl4ICA8amNoYWZmcmFpeEB3ZWJraXQub3JnPgorCisgICAgICAgIENyYXNoIGlu
c2lkZSBSZW5kZXJCbG9jazo6bGF5b3V0UnVuc0FuZEZsb2F0c0luUmFuZ2UgaW4gdGhlIHdpZG93
IGNvZGUKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTEw
ODA4NAorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIFRo
aXMgaXMgYSBibGluZCBmaXggYmFzZWQgb24gdGhlIGNvZGUgYW5kIENocm9taXVtJ3Mgc3RhY2st
dHJhY2VzLgorCisgICAgICAgIFVuZm9ydHVuYXRlbHkgbm8gbmV3IHRlc3QgYXMgSSBjb3VsZG4n
dCBnZXQgYSBsb2NhbCByZXByb2R1Y3Rpb24uCisKKyAgICAgICAgKiByZW5kZXJpbmcvUmVuZGVy
QmxvY2tMaW5lTGF5b3V0LmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OlJlbmRlckJsb2NrOjpsYXlv
dXRSdW5zQW5kRmxvYXRzSW5SYW5nZSk6CisgICAgICAgIEFkZGVkIGEgbWlzc2luZyBOVUxMLWNo
ZWNrOiB0aGUgcHJldmlvdXMgJ3doaWxlJyBmaW5pc2ggaWYgfGxpbmVCb3h8CisgICAgICAgIGlz
IE5VTEwgYW5kIHdlIGRvbid0IHdhbnQgdG8gY3Jhc2ggaW4gdGhpcyBjYXNlLgorCiAyMDEzLTAx
LTI4ICBNYXJ0aW4gUm9iaW5zb24gIDxtcm9iaW5zb25AaWdhbGlhLmNvbT4KIAogICAgICAgICBb
RnJlZXR5cGVdIFN5bnRoZXRpYyBib2xkIG5vdCBhcHBsaWVkIHRvIGZhbGxiYWNrIGZvbnRzIHBy
b3Blcmx5CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9yZW5kZXJpbmcvUmVuZGVyQmxvY2tM
aW5lTGF5b3V0LmNwcCBiL1NvdXJjZS9XZWJDb3JlL3JlbmRlcmluZy9SZW5kZXJCbG9ja0xpbmVM
YXlvdXQuY3BwCmluZGV4IGZiYjNkZGJhOTkwNjZjYjM4MTdhMGE5NDVhZTgyZDRlYzU0MjkwZDIu
LmU5NjBkMTNkNzI3MmEwMmU3YTFmMjU2ZGI5NDA1MTNhNzcwZWE0NmQgMTAwNjQ0Ci0tLSBhL1Nv
dXJjZS9XZWJDb3JlL3JlbmRlcmluZy9SZW5kZXJCbG9ja0xpbmVMYXlvdXQuY3BwCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL3JlbmRlcmluZy9SZW5kZXJCbG9ja0xpbmVMYXlvdXQuY3BwCkBAIC0xNjY3
LDcgKzE2NjcsNyBAQCB2b2lkIFJlbmRlckJsb2NrOjpsYXlvdXRSdW5zQW5kRmxvYXRzSW5SYW5n
ZShMaW5lTGF5b3V0U3RhdGUmIGxheW91dFN0YXRlLCBJbmxpbgogICAgICAgICB9CiAKICAgICAg
ICAgLy8gSWYgdGhlcmUgd2VyZSBubyBicmVha3MgaW4gdGhlIGJsb2NrLCB3ZSBkaWRuJ3QgY3Jl
YXRlIGFueSB3aWRvd3MuCi0gICAgICAgIGlmICghbGluZUJveC0+aXNGaXJzdEFmdGVyUGFnZUJy
ZWFrKCkgfHwgbGluZUJveCA9PSBmaXJzdExpbmVJbkJsb2NrKQorICAgICAgICBpZiAoIWxpbmVC
b3ggfHwgIWxpbmVCb3gtPmlzRmlyc3RBZnRlclBhZ2VCcmVhaygpIHx8IGxpbmVCb3ggPT0gZmly
c3RMaW5lSW5CbG9jaykKICAgICAgICAgICAgIHJldHVybjsKIAogICAgICAgICBpZiAobnVtTGlu
ZXNIYW5naW5nIDwgc3R5bGUoKS0+d2lkb3dzKCkpIHsK
</data>

          </attachment>
      

    </bug>

</bugzilla>