<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>12015</bug_id>
          
          <creation_ts>2006-12-28 11:44:37 -0800</creation_ts>
          <short_desc>svg/W3C-SVG-1.1/painting-marker-03-f.svg crashes</short_desc>
          <delta_ts>2006-12-28 15:41:46 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>SVG</component>
          <version>420+</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.4</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P1</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Alexey Proskuryakov">ap</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>39226</commentid>
    <comment_count>0</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2006-12-28 11:44:37 -0800</bug_when>
    <thetext>Open this test in the browser, or 
run-webkit-tests --pixel svg/W3C-SVG-1.1/painting-marker-03-f.svg
to reproduce the crash. I&apos;m running a debug build of TOT.

Thread 0 Crashed:
0   com.apple.WebCore        	0x014b0cd0 WebCore::drawStartAndMidMarkers(void*, WebCore::PathElement const*) + 104 (RenderPath.cpp:388)
1   com.apple.WebCore        	0x014d54ec WebCore::CGPathApplierToPathApplier(void*, CGPathElement const*) + 464 (PathCG.cpp:229)
2   com.apple.CoreGraphics   	0x90435c70 CGPathApply + 548
3   com.apple.WebCore        	0x014d5554 WebCore::Path::apply(void*, void (*)(void*, WebCore::PathElement const*)) const + 84 (PathCG.cpp:237)
4   com.apple.WebCore        	0x014b1034 WebCore::RenderPath::drawMarkersIfNeeded(WebCore::GraphicsContext*, WebCore::FloatRect const&amp;, WebCore::Path const&amp;) const + 628 (RenderPath.cpp:424)
5   com.apple.WebCore        	0x014b1664 WebCore::RenderPath::paint(WebCore::RenderObject::PaintInfo&amp;, int, int) + 1528 (RenderPath.cpp:206)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>39197</commentid>
    <comment_count>1</comment_count>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2006-12-28 12:22:05 -0800</bug_when>
    <thetext>I am unable to reproduce the crash in my local build.

I&apos;ll try with --guard and see if that causes a crash.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>39198</commentid>
    <comment_count>2</comment_count>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2006-12-28 12:23:27 -0800</bug_when>
    <thetext>run-webkit-tests --guard --pixel svg/W3C-SVG-1.1/painting-marker-03-f.svg
also does not crash for me.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>39187</commentid>
    <comment_count>3</comment_count>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2006-12-28 12:24:48 -0800</bug_when>
    <thetext>I&apos;m not able to reproduce this with 18457.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>39188</commentid>
    <comment_count>4</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2006-12-28 12:39:09 -0800</bug_when>
    <thetext>The problem is in CGPathApplierToPathApplier(), points[2] is out of bounds.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>39189</commentid>
    <comment_count>5</comment_count>
      <attachid>12085</attachid>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2006-12-28 12:43:43 -0800</bug_when>
    <thetext>Created attachment 12085
Fix as described by ap

I never saw it crash for me, but this should fix things.  Strange that ap was getting a crash and I was not.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>39163</commentid>
    <comment_count>6</comment_count>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2006-12-28 15:41:46 -0800</bug_when>
    <thetext>Landed in r18458 by eseidel.

</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>12085</attachid>
            <date>2006-12-28 12:43:43 -0800</date>
            <delta_ts>2006-12-28 12:51:45 -0800</delta_ts>
            <desc>Fix as described by ap</desc>
            <filename>small.patch</filename>
            <type>text/plain</type>
            <size>1203</size>
            <attacher name="Eric Seidel (no email)">eric</attacher>
            
              <data encoding="base64">SW5kZXg6IENoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBDaGFuZ2VMb2cJKHJldmlzaW9uIDE4NDU3
KQorKysgQ2hhbmdlTG9nCSh3b3JraW5nIGNvcHkpCkBAIC0xLDMgKzEsMTUgQEAKKzIwMDYtMTIt
MjggIEVyaWMgU2VpZGVsICA8ZXJpY0B3ZWJraXQub3JnPgorCisgICAgICAgIFJldmlld2VkIGJ5
IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIEZpeCBmb3IgbWVtb3J5IHNtYXNoZXIgd2hlbiBk
cmF3aW5nIG1hcmtlcnMuCisgICAgICAgIGh0dHA6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcu
Y2dpP2lkPTEyMDE1CisgICAgICAgIAorICAgICAgICBObyB0ZXN0IGNhc2UgcG9zc2libGUgKGNy
YXNoZXMgZm9yIHNvbWUgZm9sa3MgYnV0IG5vdCBvdGhlcnMsIG5vdCBldmVuIHVuZGVyIC0tZ3Vh
cmQpCisKKyAgICAgICAgKiBwbGF0Zm9ybS9ncmFwaGljcy9jZy9QYXRoQ0cuY3BwOgorICAgICAg
ICAoV2ViQ29yZTo6Q0dQYXRoQXBwbGllclRvUGF0aEFwcGxpZXIpOiBhcnJheSB3YXMgdG9vIHNt
YWxsCisKIDIwMDYtMTItMjggIE1pdHogUGV0dGVsICA8bWl0ekB3ZWJraXQub3JnPgogCiAgICAg
ICAgIFJldmlld2VkIGJ5IERhcmluLgpJbmRleDogcGxhdGZvcm0vZ3JhcGhpY3MvY2cvUGF0aENH
LmNwcAo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09Ci0tLSBwbGF0Zm9ybS9ncmFwaGljcy9jZy9QYXRoQ0cuY3BwCShyZXZp
c2lvbiAxODQ1NykKKysrIHBsYXRmb3JtL2dyYXBoaWNzL2NnL1BhdGhDRy5jcHAJKHdvcmtpbmcg
Y29weSkKQEAgLTIwMyw3ICsyMDMsNyBAQCBzdHJ1Y3QgUGF0aEFwcGxpZXJJbmZvIHsKIHZvaWQg
Q0dQYXRoQXBwbGllclRvUGF0aEFwcGxpZXIodm9pZCAqaW5mbywgY29uc3QgQ0dQYXRoRWxlbWVu
dCAqZWxlbWVudCkKIHsKICAgICBQYXRoQXBwbGllckluZm8qIHBpbmZvID0gKFBhdGhBcHBsaWVy
SW5mbyopaW5mbzsKLSAgICBGbG9hdFBvaW50IHBvaW50c1syXTsKKyAgICBGbG9hdFBvaW50IHBv
aW50c1szXTsKICAgICBQYXRoRWxlbWVudCBwZWxlbWVudDsKICAgICBwZWxlbWVudC50eXBlID0g
KFBhdGhFbGVtZW50VHlwZSllbGVtZW50LT50eXBlOwogICAgIHBlbGVtZW50LnBvaW50cyA9IHBv
aW50czsK
</data>
<flag name="review"
          id="4454"
          type_id="1"
          status="+"
          setter="rwlbuis"
    />
          </attachment>
      

    </bug>

</bugzilla>