<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>146399</bug_id>
          
          <creation_ts>2015-06-28 15:15:11 -0700</creation_ts>
          <short_desc>AX: iOS: Crash at accessibilityObjectForMainFramePlugin()</short_desc>
          <delta_ts>2015-06-28 22:06:36 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Accessibility</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="chris fleizach">cfleizach</reporter>
          <assigned_to name="chris fleizach">cfleizach</assigned_to>
          <cc>andersca</cc>
    
    <cc>beidson</cc>
    
    <cc>commit-queue</cc>
    
    <cc>ddkilzer</cc>
    
    <cc>sam</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1105306</commentid>
    <comment_count>0</comment_count>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2015-06-28 15:15:11 -0700</bug_when>
    <thetext>Exception Type:  EXC_BAD_ACCESS (SIGSEGV)
Exception Subtype: KERN_INVALID_ADDRESS at 0x00000018
Triggered by Thread:  0

Thread 0 name:  Dispatch queue: com.apple.main-thread
Thread 0 Crashed ↩:
0   WebKit                        	0x2bef7704 WebKit::WebPage::accessibilityObjectForMainFramePlugin() + 4 (memory:2644)
1   WebKit                        	0x2bf74a46 -[WKAccessibilityWebPageObjectBase accessibilityRootObjectWrapper] + 42 (WKAccessibilityWebPageObjectBase.mm:57)
2   Foundation                    	0x27ddec20 -[NSObject(NSKeyValueCoding) valueForKey:] + 220 (NSKeyValueCoding.m:380)
3   AccessibilityUtilities        	0x2c4cb8ea __57-[NSObject(UIAccessibilitySafeCategory) safeValueForKey:]_block_invoke + 26 (AXSafeValue.m:288)
4   AccessibilityUtilities        	0x2c4cbd24 -[NSObject(UIAccessibilitySafeCategory) _accessibilityPerformSafeValueKeyBlock:withKey:onClass:] + 84 (AXSafeValue.m:341)
5   AccessibilityUtilities        	0x2c4cb5f2 -[NSObject(UIAccessibilitySafeCategory) safeValueForKey:] + 230 (AXSafeValue.m:287)
6   WebProcess                    	0x252d7dae -[WKAccessibilityWebPageObjectAccessibility _initializeRootIfNecessary] + 30 (WKAccessibilityWebPageObjectAccessibility.m:141)
7   WebProcess                    	0x252d7b6e -[WKAccessibilityWebPageObjectAccessibility accessibilityHitTest:] + 26 (WKAccessibilityWebPageObjectAccessibility.m:80)
8   WebProcess                    	0x252d8bae -[WKNSObjectAccessibility accessibilityHitTest:] + 234 (NSObject+AXWebProcess.m:33)
9   AXRuntime                     	0x2c3de9c6 _copyElementAtPositionCallback + 126 (AXSimpleRuntimeManager.m:114)
10  AXRuntime                     	0x2c3e53fa _AXXMIGCopyElementAtPosition + 178 (AccessibilityPriv.m:1129)


&lt;rdar://problem/19604231&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1105307</commentid>
    <comment_count>1</comment_count>
      <attachid>255730</attachid>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2015-06-28 15:16:54 -0700</bug_when>
    <thetext>Created attachment 255730
patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1105313</commentid>
    <comment_count>2</comment_count>
      <attachid>255731</attachid>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2015-06-28 16:07:05 -0700</bug_when>
    <thetext>Created attachment 255731
patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1105339</commentid>
    <comment_count>3</comment_count>
      <attachid>255731</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2015-06-28 22:06:32 -0700</bug_when>
    <thetext>Comment on attachment 255731
patch

Clearing flags on attachment: 255731

Committed r186063: &lt;http://trac.webkit.org/changeset/186063&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1105340</commentid>
    <comment_count>4</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2015-06-28 22:06:36 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>255730</attachid>
            <date>2015-06-28 15:16:54 -0700</date>
            <delta_ts>2015-06-28 16:07:05 -0700</delta_ts>
            <desc>patch</desc>
            <filename>patch</filename>
            <type>text/plain</type>
            <size>1530</size>
            <attacher name="chris fleizach">cfleizach</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJLaXQyL0NoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2Vi
S2l0Mi9DaGFuZ2VMb2cJKHJldmlzaW9uIDE4NjA1MykKKysrIFNvdXJjZS9XZWJLaXQyL0NoYW5n
ZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE1IEBACisyMDE1LTA2LTI4ICBDaHJpcyBG
bGVpemFjaCAgPGNmbGVpemFjaEBhcHBsZS5jb20+CisKKyAgICAgICAgQVg6IGlPUzogQ3Jhc2gg
YXQgYWNjZXNzaWJpbGl0eU9iamVjdEZvck1haW5GcmFtZVBsdWdpbigpCisgICAgICAgIGh0dHBz
Oi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0xNDYzOTkKKworICAgICAgICBSZXZp
ZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBDb3VsZCBub3QgcmVwcm9kdWNlIGlz
c3VlLCBidXQgdGhlIGludmFsaWQgYWRkcmVzcyBzZWVtcyB0byBpbmRpY2F0ZSB0aGlzIGlzIGEg
bnVsbHB0ciBhY2Nlc3MgKG1haW5GcmFtZSgpIGNhbiBiZSBudWxsKS4KKworICAgICAgICAqIFdl
YlByb2Nlc3MvV2ViUGFnZS9pb3MvV2ViUGFnZUlPUy5tbToKKyAgICAgICAgKFdlYktpdDo6V2Vi
UGFnZTo6YWNjZXNzaWJpbGl0eU9iamVjdEZvck1haW5GcmFtZVBsdWdpbik6CisKIDIwMTUtMDYt
MjggIERhbiBCZXJuc3RlaW4gIDxtaXR6QGFwcGxlLmNvbT4KIAogICAgICAgICBUcmllZCB0byBm
aXggdGhlIEVGTCBidWlkIGFmdGVyIHIxODYwNDYuCkluZGV4OiBTb3VyY2UvV2ViS2l0Mi9XZWJQ
cm9jZXNzL1dlYlBhZ2UvaW9zL1dlYlBhZ2VJT1MubW0KPT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291cmNlL1dl
YktpdDIvV2ViUHJvY2Vzcy9XZWJQYWdlL2lvcy9XZWJQYWdlSU9TLm1tCShyZXZpc2lvbiAxODU2
MDgpCisrKyBTb3VyY2UvV2ViS2l0Mi9XZWJQcm9jZXNzL1dlYlBhZ2UvaW9zL1dlYlBhZ2VJT1Mu
bW0JKHdvcmtpbmcgY29weSkKQEAgLTQyNSwxMyArNDI1LDEzIEBACiAKIE5TT2JqZWN0ICpXZWJQ
YWdlOjphY2Nlc3NpYmlsaXR5T2JqZWN0Rm9yTWFpbkZyYW1lUGx1Z2luKCkKIHsKLSAgICBpZiAo
IW1fcGFnZSkKLSAgICAgICAgcmV0dXJuIDA7CisgICAgaWYgKCFtX3BhZ2UgfHwgIW1fcGFnZS0+
bWFpbkZyYW1lKCkpCisgICAgICAgIHJldHVybiBuaWw7CiAgICAgCiAgICAgaWYgKFBsdWdpblZp
ZXcqIHBsdWdpblZpZXcgPSBwbHVnaW5WaWV3Rm9yRnJhbWUoJm1fcGFnZS0+bWFpbkZyYW1lKCkp
KQogICAgICAgICByZXR1cm4gcGx1Z2luVmlldy0+YWNjZXNzaWJpbGl0eU9iamVjdCgpOwogICAg
IAotICAgIHJldHVybiAwOworICAgIHJldHVybiBuaWw7CiB9CiAgICAgCiB2b2lkIFdlYlBhZ2U6
OnJlZ2lzdGVyVUlQcm9jZXNzQWNjZXNzaWJpbGl0eVRva2Vucyhjb25zdCBJUEM6OkRhdGFSZWZl
cmVuY2UmIGVsZW1lbnRUb2tlbiwgY29uc3QgSVBDOjpEYXRhUmVmZXJlbmNlJikK
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>255731</attachid>
            <date>2015-06-28 16:07:05 -0700</date>
            <delta_ts>2015-06-28 22:06:32 -0700</delta_ts>
            <desc>patch</desc>
            <filename>patch</filename>
            <type>text/plain</type>
            <size>1590</size>
            <attacher name="chris fleizach">cfleizach</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJLaXQyL0NoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2Vi
S2l0Mi9DaGFuZ2VMb2cJKHJldmlzaW9uIDE4NjA1MykKKysrIFNvdXJjZS9XZWJLaXQyL0NoYW5n
ZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE2IEBACisyMDE1LTA2LTI4ICBDaHJpcyBG
bGVpemFjaCAgPGNmbGVpemFjaEBhcHBsZS5jb20+CisKKyAgICAgICAgQVg6IGlPUzogQ3Jhc2gg
YXQgYWNjZXNzaWJpbGl0eU9iamVjdEZvck1haW5GcmFtZVBsdWdpbigpCisgICAgICAgIGh0dHBz
Oi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0xNDYzOTkKKworICAgICAgICBSZXZp
ZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBDb3VsZCBub3QgcmVwcm9kdWNlIGlz
c3VlLCBidXQgdGhlIGludmFsaWQgYWRkcmVzcyBzZWVtcyB0byBpbmRpY2F0ZSB0aGlzIGlzIGEg
bnVsbHB0ciBhY2Nlc3MgaXMgaGFwcGVuaW5nIHdoZW4gd2UgdHJ5IHRvIGdldCB0aGUgcGx1Z2lu
IG9mIHRoZSBtX3BhZ2UgdmFyaWFibGUgd2hlbgorICAgICAgICBpdCBoYXMgbm90IGJlZW4gaW5p
dGlhbGl6ZWQuCisKKyAgICAgICAgKiBXZWJQcm9jZXNzL1dlYlBhZ2UvaW9zL1dlYlBhZ2VJT1Mu
bW06CisgICAgICAgIChXZWJLaXQ6OldlYlBhZ2U6OmFjY2Vzc2liaWxpdHlPYmplY3RGb3JNYWlu
RnJhbWVQbHVnaW4pOgorCiAyMDE1LTA2LTI4ICBEYW4gQmVybnN0ZWluICA8bWl0ekBhcHBsZS5j
b20+CiAKICAgICAgICAgVHJpZWQgdG8gZml4IHRoZSBFRkwgYnVpZCBhZnRlciByMTg2MDQ2LgpJ
bmRleDogU291cmNlL1dlYktpdDIvV2ViUHJvY2Vzcy9XZWJQYWdlL21hYy9XS0FjY2Vzc2liaWxp
dHlXZWJQYWdlT2JqZWN0QmFzZS5tbQo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2ViS2l0Mi9XZWJQ
cm9jZXNzL1dlYlBhZ2UvbWFjL1dLQWNjZXNzaWJpbGl0eVdlYlBhZ2VPYmplY3RCYXNlLm1tCShy
ZXZpc2lvbiAxODU2MDgpCisrKyBTb3VyY2UvV2ViS2l0Mi9XZWJQcm9jZXNzL1dlYlBhZ2UvbWFj
L1dLQWNjZXNzaWJpbGl0eVdlYlBhZ2VPYmplY3RCYXNlLm1tCSh3b3JraW5nIGNvcHkpCkBAIC01
NCw2ICs1NCw5IEBACiAgICAgaWYgKCFXZWJDb3JlOjpBWE9iamVjdENhY2hlOjphY2Nlc3NpYmls
aXR5RW5hYmxlZCgpKQogICAgICAgICBXZWJDb3JlOjpBWE9iamVjdENhY2hlOjplbmFibGVBY2Nl
c3NpYmlsaXR5KCk7CiAKKyAgICBpZiAoIW1fcGFnZSkKKyAgICAgICAgcmV0dXJuIG5pbDsKKyAg
ICAKICAgICBOU09iamVjdCogbWFpbkZyYW1lUGx1Z2luQWNjZXNzaWJpbGl0eU9iamVjdFdyYXBw
ZXIgPSBtX3BhZ2UtPmFjY2Vzc2liaWxpdHlPYmplY3RGb3JNYWluRnJhbWVQbHVnaW4oKTsKICAg
ICBpZiAobWFpbkZyYW1lUGx1Z2luQWNjZXNzaWJpbGl0eU9iamVjdFdyYXBwZXIpCiAgICAgICAg
IHJldHVybiBtYWluRnJhbWVQbHVnaW5BY2Nlc3NpYmlsaXR5T2JqZWN0V3JhcHBlcjsK
</data>

          </attachment>
      

    </bug>

</bugzilla>