<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>12191</bug_id>
          
          <creation_ts>2007-01-10 02:25:19 -0800</creation_ts>
          <short_desc>crash when getting property of NodeList</short_desc>
          <delta_ts>2007-01-12 08:10:35 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>DOM</component>
          <version>419.x</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.4</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>nrlz</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>35951</commentid>
    <comment_count>0</comment_count>
    <who name="">nrlz</who>
    <bug_when>2007-01-10 02:25:19 -0800</bug_when>
    <thetext>I can crash Safari 419.3 with the following HTML:

&lt;script&gt;
var n = document.createElement(&quot;DIV&quot;);
n.appendChild(document.createTextNode(&quot;&quot;));
n.childNodes.slice;
&lt;/script&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>35923</commentid>
    <comment_count>1</comment_count>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2007-01-10 05:57:54 -0800</bug_when>
    <thetext>Confirmed with Safari 2.0.4 (419.3) on Mac OS X 10.4.8 (8L127).

Radar: &lt;rdar://problem/4916817&gt;

</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>35925</commentid>
    <comment_count>2</comment_count>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2007-01-10 05:59:27 -0800</bug_when>
    <thetext>Testing on a locally-built debug build of WebKit r18731 with Safari 2.0.4 (419.3) and Mac OS X 10.4.8 (8L127), this does not cause a crash.  Therefore closing this bug as RESOLVED/FIXED.

</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>35763</commentid>
    <comment_count>3</comment_count>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2007-01-11 03:36:24 -0800</bug_when>
    <thetext>Note that reproducing the crash requires clicking the Reload button as fast as possible (once the initial page has loaded) until Safari crashes.

On shipping Safari 2.0.4 (419.3), the crash happens on the initial load, or the first reload.

On the first WebKit nightly from CVS (WebKit-CVS-2005-10-01 03:27:01 GMT.dmg), you must reload about 5 times.

On the first WebKit nightly from SVN (WebKit-SVN-r11976.dmg), you must reload about 20 times.

At r12161, it takes over 30 times.

At r12162, it takes over 40 times.

During the binary search of WebKit nightlies, I found that between r12190 (over 40 times) and r12443 (doesn&apos;t crash over 100 times) there was a fix, then there was a regression between r12443 and r12899 (over 40 times to crash), and another fix between r12904 and r12930.
</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>35527</commentid>
    <comment_count>4</comment_count>
      <attachid>12383</attachid>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2007-01-12 07:08:57 -0800</bug_when>
    <thetext>Created attachment 12383
Torture test (hangs if fixed, else crashes)


This is a torture test for this bug.  It replaces having to click on Reload as fast as you can to reproduce the bug, and will probably extend the life of your mouse&apos;s clicker.  :)

If the bug is fixed, Safari will hang but not crash.

If the bug is still present, Safari will crash within 5 seconds or so (not including the time it takes crashreporter to do its thing).

I found that with the same revision (e.g., r12930), the WebKit nightly (release) build is fixed, but a locally-built debug build still fails.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>35508</commentid>
    <comment_count>5</comment_count>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2007-01-12 08:10:35 -0800</bug_when>
    <thetext>(In reply to comment #4)
&gt; I found that with the same revision (e.g., r12930), the WebKit nightly
&gt; (release) build is fixed, but a locally-built debug build still fails.

Confirmed that the bug is fixed in nightly r18794 (release build) and a locally-built debug build of r18802 with the torture test.

</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>12383</attachid>
            <date>2007-01-12 07:08:57 -0800</date>
            <delta_ts>2007-01-12 08:14:56 -0800</delta_ts>
            <desc>Torture test (hangs if fixed, else crashes)
</desc>
            <filename>bug-12191-torture-test.html</filename>
            <type>text/html</type>
            <size>136</size>
            <attacher name="David Kilzer (:ddkilzer)">ddkilzer</attacher>
            
              <data encoding="base64">PHNjcmlwdD4Kd2hpbGUgKDEpIHsKdmFyIG4gPSBkb2N1bWVudC5jcmVhdGVFbGVtZW50KCJESVYi
KTsKbi5hcHBlbmRDaGlsZChkb2N1bWVudC5jcmVhdGVUZXh0Tm9kZSgiIikpOwpuLmNoaWxkTm9k
ZXMuc2xpY2U7Cn0KPC9zY3JpcHQ+Cg==
</data>

          </attachment>
      

    </bug>

</bugzilla>