<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>143591</bug_id>
          
          <creation_ts>2015-04-09 17:15:14 -0700</creation_ts>
          <short_desc>Regression(r182603): editing/selection/selection-invalid-offset.html is crashing</short_desc>
          <delta_ts>2015-04-09 17:40:29 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebCore Misc.</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>142536</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="Chris Dumez">cdumez</reporter>
          <assigned_to name="Chris Dumez">cdumez</assigned_to>
          <cc>ap</cc>
    
    <cc>commit-queue</cc>
    
    <cc>enrica</cc>
    
    <cc>rniwa</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1084140</commentid>
    <comment_count>0</comment_count>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2015-04-09 17:15:14 -0700</bug_when>
    <thetext>editing/selection/selection-invalid-offset.html is crashing:
Exception Type:  EXC_BAD_ACCESS (SIGSEGV)
Exception Codes: KERN_INVALID_ADDRESS at 0x0000000000000000

VM Regions Near 0:
--&gt; 
    __TEXT                 00000001024ef000-00000001024f1000 [    8K] r-x/rwx SM=COW  /Volumes/VOLUME/*/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.Development.xpc/Contents/MacOS/com.apple.WebKit.WebContent.Development

Application Specific Information:
CRASHING TEST: editing/selection/selection-in-iframe-removed-crash.html

Thread 0 Crashed:: Dispatch queue: com.apple.main-thread
0   com.apple.WebCore             	0x000000010bbe7c01 WebCore::FrameSelection::updateAndRevealSelection() + 337 (FrameSelection.cpp:385)
1   com.apple.WebCore             	0x000000010bbe6134 WebCore::FrameSelection::setSelection(WebCore::VisibleSelection const&amp;, unsigned int, WebCore::FrameSelection::CursorAlignOnScroll, WebCore::TextGranularity) + 308 (FrameSelection.cpp:345)
2   com.apple.WebCore             	0x000000010bbe716c WebCore::FrameSelection::setSelectionWithoutUpdatingAppearance(WebCore::VisibleSelection const&amp;, unsigned int, WebCore::FrameSelection::CursorAlignOnScroll, WebCore::TextGranularity) + 492 (FrameSelection.cpp:279)
3   com.apple.WebCore             	0x000000010bbe6043 WebCore::FrameSelection::setSelection(WebCore::VisibleSelection const&amp;, unsigned int, WebCore::FrameSelection::CursorAlignOnScroll, WebCore::TextGranularity) + 67 (FrameSelection.cpp:325)
4   com.apple.WebCore             	0x000000010bbe63ac WebCore::FrameSelection::moveTo(WebCore::Range const*) + 252 (FrameSelection.cpp:159)
5   com.apple.WebCore             	0x000000010b973a5b WebCore::DOMSelection::addRange(WebCore::Range*) + 123 (DOMSelection.cpp:392)
6   com.apple.WebCore             	0x000000010c1f348c WebCore::jsDOMSelectionPrototypeFunctionAddRange(JSC::ExecState*) + 492 (JSDOMSelection.cpp:562)
7   ???                           	0x000024e7f1201028 0 + 40578601455656
8   com.apple.JavaScriptCore      	0x0000000109a39946 llint_entry + 25850
9   com.apple.JavaScriptCore      	0x0000000109a39946 llint_entry + 25850
10  com.apple.JavaScriptCore      	0x0000000109a33209 vmEntryToJavaScript + 361
11  com.apple.JavaScriptCore      	0x000000010989c69a JSC::JITCode::execute(JSC::VM*, JSC::ProtoCallFrame*) + 266 (JITCode.cpp:77)
12  com.apple.JavaScriptCore      	0x000000010987fd01 JSC::Interpreter::execute(JSC::ProgramExecutable*, JSC::ExecState*, JSC::JSObject*) + 4849 (Interpreter.cpp:857)
13  com.apple.JavaScriptCore      	0x00000001093ceb00 JSC::evaluate(JSC::ExecState*, JSC::SourceCode const&amp;, JSC::JSValue, JSC::JSValue*) + 480 (Completion.cpp:83)
14  com.apple.WebCore             	0x000000010c3bb075 WebCore::JSMainThreadExecState::evaluate(JSC::ExecState*, JSC::SourceCode const&amp;, JSC::JSValue, JSC::JSValue*) + 69 (JSMainThreadExecState.h:62)
15  com.apple.WebCore             	0x000000010cdb49bd WebCore::ScriptController::evaluateInWorld(WebCore::ScriptSourceCode const&amp;, WebCore::DOMWrapperWorld&amp;) + 317 (ScriptController.cpp:165)
16  com.apple.WebCore             	0x000000010cdb6233 WebCore::ScriptController::executeScriptInWorld(WebCore::DOMWrapperWorld&amp;, WTF::String const&amp;, bool) + 307 (ScriptController.cpp:515)
17  com.apple.WebCore             	0x000000010cdaa9ef WebCore::ScheduledAction::execute(WebCore::Document&amp;) + 351 (ScheduledAction.cpp:127)
18  com.apple.WebCore             	0x000000010cdaa863 WebCore::ScheduledAction::execute(WebCore::ScriptExecutionContext&amp;) + 67 (ScheduledAction.cpp:78)
19  com.apple.WebCore             	0x000000010b979100 WebCore::DOMTimer::fired() + 896 (DOMTimer.cpp:399)
20  com.apple.WebCore             	0x000000010d21d09c WebCore::ThreadTimers::sharedTimerFiredInternal() + 396 (ThreadTimers.cpp:135)
21  com.apple.WebCore             	0x000000010d21cd59 WebCore::ThreadTimers::sharedTimerFired() + 25 (ThreadTimers.cpp:108)
22  com.apple.WebCore             	0x000000010c3d9a8a WebCore::timerFired(__CFRunLoopTimer*, void*) + 42 (SharedTimerCF.cpp:83)
23  com.apple.CoreFoundation      	0x00007fff8e9c03e4 __CFRUNLOOP_IS_CALLING_OUT_TO_A_TIMER_CALLBACK_FUNCTION__ + 20
24  com.apple.CoreFoundation      	0x00007fff8e9bff1f __CFRunLoopDoTimer + 1151
25  com.apple.CoreFoundation      	0x00007fff8ea315aa __CFRunLoopDoTimers + 298
26  com.apple.CoreFoundation      	0x00007fff8e97b6a5 __CFRunLoopRun + 1525
27  com.apple.CoreFoundation      	0x00007fff8e97ae75 CFRunLoopRunSpecific + 309
28  com.apple.HIToolbox           	0x00007fff85021a0d RunCurrentEventLoopInMode + 226
29  com.apple.HIToolbox           	0x00007fff850217b7 ReceiveNextEventCommon + 479
30  com.apple.HIToolbox           	0x00007fff850215bc _BlockUntilNextEventMatchingListInModeWithFilter + 65
31  com.apple.AppKit              	0x00007fff8ee8a24e _DPSNextEvent + 1434
32  com.apple.AppKit              	0x00007fff8ee8989b -[NSApplication nextEventMatchingMask:untilDate:inMode:dequeue:] + 122
33  com.apple.AppKit              	0x00007fff8ee7d99c -[NSApplication run] + 553
34  com.apple.AppKit              	0x00007fff8ee68783 NSApplicationMain + 940
35  com.apple.XPCService          	0x00007fff8cb13c0f _xpc_main + 385
36  libxpc.dylib                  	0x00007fff84dc1bde xpc_main + 399
37  com.apple.WebKit.WebContent.Development	0x00000001024f0195 main + 37
38  libdyld.dylib                 	0x00007fff8c6985fd start + 1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1084142</commentid>
    <comment_count>1</comment_count>
      <attachid>250489</attachid>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2015-04-09 17:17:17 -0700</bug_when>
    <thetext>Created attachment 250489
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1084152</commentid>
    <comment_count>2</comment_count>
      <attachid>250489</attachid>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2015-04-09 17:40:23 -0700</bug_when>
    <thetext>Comment on attachment 250489
Patch

Clearing flags on attachment: 250489

Committed r182619: &lt;http://trac.webkit.org/changeset/182619&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1084153</commentid>
    <comment_count>3</comment_count>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2015-04-09 17:40:29 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>250489</attachid>
            <date>2015-04-09 17:17:17 -0700</date>
            <delta_ts>2015-04-09 17:40:23 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-143591-20150409171625.patch</filename>
            <type>text/plain</type>
            <size>1473</size>
            <attacher name="Chris Dumez">cdumez</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTgyNjA1CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggMmQyZjlhNDk0ZDI3MWI4
MzdhYjUwOWEwYmFhMmJlYzM4NWUyZTE2Zi4uMjUyMGZiMjljZTcyZjVlYWJmZDdlNTNmZWNmM2Ni
ZjExNTBmOWJjZSAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDE2IEBACisyMDE1LTA0LTA5ICBDaHJp
cyBEdW1leiAgPGNkdW1lekBhcHBsZS5jb20+CisKKyAgICAgICAgUmVncmVzc2lvbihyMTgyNjAz
KTogZWRpdGluZy9zZWxlY3Rpb24vc2VsZWN0aW9uLWludmFsaWQtb2Zmc2V0Lmh0bWwgaXMgY3Jh
c2hpbmcKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTE0
MzU5MQorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIEFk
ZCBtaXNzaW5nIG51bGwtY2hlY2sgZm9yIG1fZnJhbWUtPmVkaXRvcigpLmNsaWVudCgpIGluCisg
ICAgICAgIEZyYW1lU2VsZWN0aW9uOjp1cGRhdGVBbmRSZXZlYWxTZWxlY3Rpb24oKS4KKworICAg
ICAgICAqIGVkaXRpbmcvRnJhbWVTZWxlY3Rpb24uY3BwOgorICAgICAgICAoV2ViQ29yZTo6RnJh
bWVTZWxlY3Rpb246OnVwZGF0ZUFuZFJldmVhbFNlbGVjdGlvbik6CisKIDIwMTUtMDQtMDkgIFNp
bW9uIEZyYXNlciAgPHNpbW9uLmZyYXNlckBhcHBsZS5jb20+CiAKICAgICAgICAgUmV2ZXJ0IHBh
cnQgb2YgMTgyNTE2OiBpdCBicm9rZSB0ZXN0cwpkaWZmIC0tZ2l0IGEvU291cmNlL1dlYkNvcmUv
ZWRpdGluZy9GcmFtZVNlbGVjdGlvbi5jcHAgYi9Tb3VyY2UvV2ViQ29yZS9lZGl0aW5nL0ZyYW1l
U2VsZWN0aW9uLmNwcAppbmRleCBlMzliZmM2MTZmYjQ4OWQ3ZjNmZDc0YzI2OTM5YmM5MmE2MmIx
ZjEwLi41NzQ1MTcwYzc3MDUzMmEyOGZhNmRmZGE3NDA3NTU0OWU1M2U2YWMzIDEwMDY0NAotLS0g
YS9Tb3VyY2UvV2ViQ29yZS9lZGl0aW5nL0ZyYW1lU2VsZWN0aW9uLmNwcAorKysgYi9Tb3VyY2Uv
V2ViQ29yZS9lZGl0aW5nL0ZyYW1lU2VsZWN0aW9uLmNwcApAQCAtMzgyLDcgKzM4Miw4IEBAIHZv
aWQgRnJhbWVTZWxlY3Rpb246OnVwZGF0ZUFuZFJldmVhbFNlbGVjdGlvbigpCiAKICAgICBub3Rp
ZnlBY2Nlc3NpYmlsaXR5Rm9yU2VsZWN0aW9uQ2hhbmdlKCk7CiAKLSAgICBtX2ZyYW1lLT5lZGl0
b3IoKS5jbGllbnQoKS0+ZGlkQ2hhbmdlU2VsZWN0aW9uQW5kVXBkYXRlTGF5b3V0KCk7CisgICAg
aWYgKGF1dG8qIGNsaWVudCA9IG1fZnJhbWUtPmVkaXRvcigpLmNsaWVudCgpKQorICAgICAgICBj
bGllbnQtPmRpZENoYW5nZVNlbGVjdGlvbkFuZFVwZGF0ZUxheW91dCgpOwogfQogCiB2b2lkIEZy
YW1lU2VsZWN0aW9uOjp1cGRhdGVEYXRhRGV0ZWN0b3JzRm9yU2VsZWN0aW9uKCkK
</data>

          </attachment>
      

    </bug>

</bugzilla>