<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>149299</bug_id>
          
          <creation_ts>2015-09-17 14:56:36 -0700</creation_ts>
          <short_desc>Null dereference loading Blink layout test editing/inserting/insert-with-mutation-event.html</short_desc>
          <delta_ts>2015-10-14 13:12:00 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>HTML Editing</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>BlinkMergeCandidate, HasReduction, InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Jon Honeycutt">jhoneycutt</reporter>
          <assigned_to name="Jiewen Tan">jiewen_tan</assigned_to>
          <cc>commit-queue</cc>
    
    <cc>esprehn+autocc</cc>
    
    <cc>jiewen_tan</cc>
    
    <cc>kangil.han</cc>
    
    <cc>kling</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1126876</commentid>
    <comment_count>0</comment_count>
      <attachid>261434</attachid>
    <who name="Jon Honeycutt">jhoneycutt</who>
    <bug_when>2015-09-17 14:56:36 -0700</bug_when>
    <thetext>Created attachment 261434
crashing test

Null dereference loading Blink layout test editing/inserting/insert-with-mutation-event.html.

Stack trace:

Crashed Thread:        0  Dispatch queue: com.apple.main-thread

Exception Type:        EXC_BAD_ACCESS (SIGSEGV)
Exception Codes:       KERN_INVALID_ADDRESS at 0x0000000000000348
Exception Note:        EXC_CORPSE_NOTIFY

VM Regions Near 0x348:
--&gt; 
    __TEXT                 00000001029e4000-00000001029e6000 [    8K] r-x/rwx SM=COW  /Users/USER/*/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.Development.xpc/Contents/MacOS/com.apple.WebKit.WebContent.Development

Application Specific Information:
CRASHING TEST: temp-tests/editing/inserting/insert-with-mutation-event.html

Global Trace Buffer (reverse chronological seconds):
40.565241    CFNetwork                 	0x00007fff88d43b97 Explicitly setting CF cookie storage singleton
40.565623    CFNetwork                 	0x00007fff88d8f211 Explicitly setting cookie storage singleton

Thread 0 Crashed:: Dispatch queue: com.apple.main-thread
0   com.apple.WebCore             	0x000000010aa177da WebCore::SimpleEditCommand::SimpleEditCommand(WebCore::Document&amp;, WebCore::EditAction) + 90 (memory:2635)
1   com.apple.WebCore             	0x000000010b4afde5 WebCore::SplitTextNodeCommand::SplitTextNodeCommand(WTF::PassRefPtr&lt;WebCore::Text&gt;, int) + 37 (SplitTextNodeCommand.cpp:40)
2   com.apple.WebCore             	0x000000010a80317f WebCore::CompositeEditCommand::splitTextNode(WTF::PassRefPtr&lt;WebCore::Text&gt;, unsigned int) + 63 (StdLibExtras.h:366)
3   com.apple.WebCore             	0x000000010a7527a1 WebCore::ApplyStyleCommand::splitTextAtStart(WebCore::Position const&amp;, WebCore::Position const&amp;) + 161 (StdLibExtras.h:366)
4   com.apple.WebCore             	0x000000010a750963 WebCore::ApplyStyleCommand::applyInlineStyle(WebCore::EditingStyle*) + 723 (ApplyStyleCommand.cpp:189)
5   com.apple.WebCore             	0x000000010a74e0fd WebCore::ApplyStyleCommand::doApply() + 173 (PassRefPtr.h:41)
6   com.apple.WebCore             	0x000000010a80252b WebCore::CompositeEditCommand::applyCommandToComposite(WTF::PassRefPtr&lt;WebCore::EditCommand&gt;) + 43 (CompositeEditCommand.cpp:281)
7   com.apple.WebCore             	0x000000010a8026dc WebCore::CompositeEditCommand::applyStyle(WebCore::EditingStyle const*, WebCore::EditAction) + 76 (StdLibExtras.h:366)
8   com.apple.WebCore             	0x000000010ac8912d WebCore::InsertTextCommand::doApply() + 2205 (RefCounted.h:99)
9   com.apple.WebCore             	0x000000010a802630 WebCore::CompositeEditCommand::applyCommandToComposite(WTF::PassRefPtr&lt;WebCore::CompositeEditCommand&gt;, WebCore::VisibleSelection const&amp;) + 80 (CompositeEditCommand.cpp:296)
10  com.apple.WebCore             	0x000000010b64dc13 WebCore::TypingCommand::insertTextRunWithoutNewlines(WTF::String const&amp;, bool) + 115 (StdLibExtras.h:366)
11  com.apple.WebCore             	0x000000010b64e091 void WebCore::forEachLineInString&lt;WebCore::TypingCommandLineOperation&gt;(WTF::String const&amp;, WebCore::TypingCommandLineOperation const&amp;) + 257 (StdLibExtras.h:366)
12  com.apple.WebCore             	0x000000010b64cae8 WebCore::TypingCommand::insertText(WebCore::Document&amp;, WTF::String const&amp;, WebCore::VisibleSelection const&amp;, unsigned int, WebCore::TypingCommand::TextCompositionType) + 440 (RefCounted.h:99)
13  com.apple.WebCore             	0x000000010aa3629a WebCore::executeInsertText(WebCore::Frame&amp;, WebCore::Event*, WebCore::EditorCommandSource, WTF::String const&amp;) + 26 (EditorCommand.cpp:535)
14  com.apple.WebCore             	0x000000010aa34876 WebCore::Editor::Command::execute(WTF::String const&amp;, WebCore::Event*) const + 182 (EditorCommand.cpp:1704)
15  com.apple.WebCore             	0x000000010a96dc36 WebCore::Document::execCommand(WTF::String const&amp;, bool, WTF::String const&amp;) + 214 (Document.cpp:4666)
16  com.apple.WebCore             	0x000000010ad84074 WebCore::jsDocumentPrototypeFunctionExecCommand(JSC::ExecState*) + 420 (JSCJSValue.h:499)
17  ???                           	0x00002c99c3201028 0 + 49038915276840
18  com.apple.JavaScriptCore      	0x000000010a0e076f llint_entry + 22696
19  com.apple.JavaScriptCore      	0x000000010a0dace4 vmEntryToJavaScript + 299
20  com.apple.JavaScriptCore      	0x0000000109f9b2d9 JSC::JITCode::execute(JSC::VM*, JSC::ProtoCallFrame*) + 169 (JITCode.cpp:82)
21  com.apple.JavaScriptCore      	0x0000000109f81a10 JSC::Interpreter::execute(JSC::ProgramExecutable*, JSC::ExecState*, JSC::JSObject*) + 10448 (Interpreter.cpp:945)
22  com.apple.JavaScriptCore      	0x0000000109c944c5 JSC::evaluate(JSC::ExecState*, JSC::SourceCode const&amp;, JSC::JSValue, WTF::NakedPtr&lt;JSC::Exception&gt;&amp;) + 469 (Completion.cpp:104)
23  com.apple.WebCore             	0x000000010b3f78ec WebCore::ScriptController::evaluateInWorld(WebCore::ScriptSourceCode const&amp;, WebCore::DOMWrapperWorld&amp;) + 284 (JSMainThreadExecState.h:62)
24  com.apple.WebCore             	0x000000010b3f7b29 WebCore::ScriptController::evaluate(WebCore::ScriptSourceCode const&amp;) + 41 (ScriptController.cpp:180)
25  com.apple.WebCore             	0x000000010b3fdaac WebCore::ScriptElement::executeScript(WebCore::ScriptSourceCode const&amp;) + 316 (ScriptElement.cpp:309)
26  com.apple.WebCore             	0x000000010b3fc756 WebCore::ScriptElement::prepareScript(WTF::TextPosition const&amp;, WebCore::ScriptElement::LegacyTypeSupport) + 1046 (StdLibExtras.h:366)
27  com.apple.WebCore             	0x000000010abf95eb WebCore::HTMLScriptRunner::runScript(WebCore::Element*, WTF::TextPosition const&amp;) + 347 (ScriptElement.h:58)
28  com.apple.WebCore             	0x000000010abf9440 WebCore::HTMLScriptRunner::execute(WTF::PassRefPtr&lt;WebCore::Element&gt;, WTF::TextPosition const&amp;) + 48 (HTMLScriptRunner.cpp:191)
29  com.apple.WebCore             	0x000000010ab9c466 WebCore::HTMLDocumentParser::runScriptsForPausedTreeBuilder() + 86 (StdLibExtras.h:366)
30  com.apple.WebCore             	0x000000010ab9c52d WebCore::HTMLDocumentParser::canTakeNextToken(WebCore::HTMLDocumentParser::SynchronousMode, WebCore::PumpSession&amp;) + 93 (HTMLDocumentParser.cpp:214)
31  com.apple.WebCore             	0x000000010ab9c0c3 WebCore::HTMLDocumentParser::pumpTokenizer(WebCore::HTMLDocumentParser::SynchronousMode) + 595 (HTMLDocumentParser.cpp:259)
32  com.apple.WebCore             	0x000000010ab9cddd WebCore::HTMLDocumentParser::append(WTF::PassRefPtr&lt;WTF::StringImpl&gt;) + 669 (DocumentParser.h:71)
33  com.apple.WebCore             	0x000000010a93f61c WebCore::DecodedDataDocumentParser::flush(WebCore::DocumentWriter&amp;) + 92 (StdLibExtras.h:366)
34  com.apple.WebCore             	0x000000010a99f68b WebCore::DocumentWriter::end() + 43 (RefPtr.h:71)
35  com.apple.WebCore             	0x000000010a9879ec WebCore::DocumentLoader::finishedLoading(double) + 268 (ResourceErrorBase.h:42)
36  com.apple.WebCore             	0x000000010a7b8179 WebCore::CachedResource::checkNotify() + 153 (CachedResourceClientWalker.h:51)
37  com.apple.WebCore             	0x000000010a7b4433 WebCore::CachedRawResource::finishLoading(WebCore::SharedBuffer*) + 227 (CachedRawResource.cpp:104)
38  com.apple.WebCore             	0x000000010b52f501 WebCore::SubresourceLoader::didFinishLoading(double) + 1153 (ResourceLoader.h:154)
39  com.apple.WebKit              	0x000000010907598d WebKit::WebResourceLoader::didReceiveWebResourceLoaderMessage(IPC::Connection&amp;, IPC::MessageDecoder&amp;) + 561 (HandleMessage.h:16)
40  com.apple.WebKit              	0x0000000108e4f1f1 IPC::Connection::dispatchMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;) + 127 (memory:2636)
41  com.apple.WebKit              	0x0000000108e51b4a IPC::Connection::dispatchOneMessage() + 126 (memory:2656)
42  com.apple.JavaScriptCore      	0x000000010a293985 WTF::RunLoop::performWork() + 437 (functional:1742)
43  com.apple.JavaScriptCore      	0x000000010a293d32 WTF::RunLoop::performWork(void*) + 34 (RunLoopCF.cpp:39)
44  com.apple.CoreFoundation      	0x00007fff949e2c01 __CFRUNLOOP_IS_CALLING_OUT_TO_A_SOURCE0_PERFORM_FUNCTION__ + 17
45  com.apple.CoreFoundation      	0x00007fff949d4b1c __CFRunLoopDoSources0 + 556
46  com.apple.CoreFoundation      	0x00007fff949d403f __CFRunLoopRun + 927
47  com.apple.CoreFoundation      	0x00007fff949d3a38 CFRunLoopRunSpecific + 296
48  com.apple.HIToolbox           	0x00007fff88e673bd RunCurrentEventLoopInMode + 235
49  com.apple.HIToolbox           	0x00007fff88e67153 ReceiveNextEventCommon + 432
50  com.apple.HIToolbox           	0x00007fff88e66f93 _BlockUntilNextEventMatchingListInModeWithFilter + 71
51  com.apple.AppKit              	0x00007fff870b81e7 _DPSNextEvent + 1076
52  com.apple.AppKit              	0x00007fff8748490d -[NSApplication _nextEventMatchingEventMask:untilDate:inMode:dequeue:] + 454
53  com.apple.AppKit              	0x00007fff870ae0b8 -[NSApplication run] + 682
54  com.apple.AppKit              	0x00007fff87030396 NSApplicationMain + 1176
55  libxpc.dylib                  	0x00007fff8c70ff70 _xpc_objc_main + 793
56  libxpc.dylib                  	0x00007fff8c7116bf xpc_main + 494
57  com.apple.WebKit.WebContent.Development	0x00000001029e5424 main + 409 (XPCServiceMain.Development.mm:187)
58  libdyld.dylib                 	0x00007fff93aa15ad start + 1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1126877</commentid>
    <comment_count>1</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2015-09-17 14:56:53 -0700</bug_when>
    <thetext>&lt;rdar://problem/22746995&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1132054</commentid>
    <comment_count>2</comment_count>
      <attachid>262804</attachid>
    <who name="Jiewen Tan">jiewen_tan</who>
    <bug_when>2015-10-09 17:24:31 -0700</bug_when>
    <thetext>Created attachment 262804
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1132773</commentid>
    <comment_count>3</comment_count>
      <attachid>262804</attachid>
    <who name="Andreas Kling">kling</who>
    <bug_when>2015-10-13 08:36:58 -0700</bug_when>
    <thetext>Comment on attachment 262804
Patch

r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1132918</commentid>
    <comment_count>4</comment_count>
    <who name="Jiewen Tan">jiewen_tan</who>
    <bug_when>2015-10-13 14:55:28 -0700</bug_when>
    <thetext>Jiewens-Mac-Pro:LayoutTests jwtan$ run-webkit-tests -g --repeat-each=10 http/tests/misc/detach-during-notifyDone.html
Using port &apos;mac-elcapitan-wk2&apos;
Test configuration: &lt;elcapitan, x86_64, debug&gt;
Placing test results in /Users/jwtan/Documents/Build/Products/Debug/layout-test-results
Baseline search path: mac-wk2 -&gt; wk2 -&gt; mac -&gt; generic
Using Debug build
Pixel tests disabled
Regular timeout: 350000, slow test timeout: 1750000
Command line: /Users/jwtan/Documents/Build/Products/Debug/WebKitTestRunner -

--lint-test-files warnings:
LayoutTests/platform/mac/TestExpectations:973 Path does not exist. media/video-double.html

Found 1 test; running 1 (10 times each: --repeat-each=10 --iterations=1), skipping 0.
Running 1 WebKitTestRunner.     

[2/10] http/tests/misc/detach-during-notifyDone.html failed unexpectedly (com.apple.WebKit.WebContent.Development crashed [pid=89460])
[4/10] http/tests/misc/detach-during-notifyDone.html failed unexpectedly (com.apple.WebKit.WebContent.Development crashed [pid=89557])
[6/10] http/tests/misc/detach-during-notifyDone.html failed unexpectedly (com.apple.WebKit.WebContent.Development crashed [pid=89562])
[8/10] http/tests/misc/detach-during-notifyDone.html failed unexpectedly (com.apple.WebKit.WebContent.Development crashed [pid=89566])
[10/10] http/tests/misc/detach-during-notifyDone.html failed unexpectedly (com.apple.WebKit.WebContent.Development crashed [pid=89571])
                        
Retrying 1 unexpected failure ...

Running 1 WebKitTestRunner.

                                                   
5 tests ran as expected, 5 didn&apos;t:


Regressions: Unexpected crashes (1)
  http/tests/misc/detach-during-notifyDone.html [ Crash ]</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1132920</commentid>
    <comment_count>5</comment_count>
    <who name="Jiewen Tan">jiewen_tan</who>
    <bug_when>2015-10-13 14:56:13 -0700</bug_when>
    <thetext>Crashed Thread:        0  Dispatch queue: com.apple.main-thread

Exception Type:        EXC_BAD_ACCESS (SIGSEGV)
Exception Codes:       KERN_INVALID_ADDRESS at 0x0000000000000bd8
Exception Note:        EXC_CORPSE_NOTIFY

Application Specific Information:
This process is running with libgmalloc.dylib (GuardMalloc) which may have forced the crash due to a memory access error.
 
CRASHING TEST: /misc/detach-during-notifyDone.html

Global Trace Buffer (reverse chronological seconds):
18446743968.919937 CFNetwork                 	0x00007fff929903eb Explicitly setting CF cookie storage singleton
18446743968.920921 CFNetwork                 	0x00007fff929c6c85 Explicitly setting cookie storage singleton

Thread 0 Crashed:: Dispatch queue: com.apple.main-thread
0   com.apple.WebKit              	0x000000011c79b28c WebKit::WebDocumentLoader::navigationID() const + 12 (WebDocumentLoader.h:40)
1   com.apple.WebKit              	0x000000011c79590d WebKit::WebFrameLoaderClient::dispatchDidFinishLoad() + 173 (WebFrameLoaderClient.cpp:553)
2   com.apple.WebCore             	0x00000001222a489d WebCore::FrameLoader::checkLoadCompleteForThisFrame() + 1853 (FrameLoader.cpp:2283)
3   com.apple.WebCore             	0x000000012229c8e0 WebCore::FrameLoader::checkLoadComplete() + 320 (FrameLoader.cpp:2461)
4   com.apple.WebCore             	0x0000000121f6c51f WebCore::DocumentLoader::finishedLoading(double) + 495 (DocumentLoader.cpp:446)
5   com.apple.WebCore             	0x0000000121f6c29e WebCore::DocumentLoader::notifyFinished(WebCore::CachedResource*) + 270 (DocumentLoader.cpp:385)
6   com.apple.WebCore             	0x0000000121b20622 WebCore::CachedResource::checkNotify() + 130 (CachedResource.cpp:296)
7   com.apple.WebCore             	0x0000000121b20731 WebCore::CachedResource::finishLoading(WebCore::SharedBuffer*) + 49 (CachedResource.cpp:314)
8   com.apple.WebCore             	0x0000000121b1c16a WebCore::CachedRawResource::finishLoading(WebCore::SharedBuffer*) + 218 (CachedRawResource.cpp:104)
9   com.apple.WebCore             	0x0000000123861295 WebCore::SubresourceLoader::didFinishLoading(double) + 517 (SubresourceLoader.cpp:374)
10  com.apple.WebKit              	0x000000011caad877 WebKit::WebResourceLoader::didFinishResourceLoad(double) + 151 (WebResourceLoader.cpp:156)
11  com.apple.WebKit              	0x000000011cab2d43 void IPC::callMemberFunctionImpl&lt;WebKit::WebResourceLoader, void (WebKit::WebResourceLoader::*)(double), std::__1::tuple&lt;double&gt;, 0ul&gt;(WebKit::WebResourceLoader*, void (WebKit::WebResourceLoader::*)(double), std::__1::tuple&lt;double&gt;&amp;&amp;, std::index_sequence&lt;0ul&gt;) + 163 (HandleMessage.h:17)
12  com.apple.WebKit              	0x000000011cab2c98 void IPC::callMemberFunction&lt;WebKit::WebResourceLoader, void (WebKit::WebResourceLoader::*)(double), std::__1::tuple&lt;double&gt;, std::make_index_sequence&lt;1ul&gt; &gt;(std::__1::tuple&lt;double&gt;&amp;&amp;, WebKit::WebResourceLoader*, void (WebKit::WebResourceLoader::*)(double)) + 88 (HandleMessage.h:23)
13  com.apple.WebKit              	0x000000011cab1dcd void IPC::handleMessage&lt;Messages::WebResourceLoader::DidFinishResourceLoad, WebKit::WebResourceLoader, void (WebKit::WebResourceLoader::*)(double)&gt;(IPC::MessageDecoder&amp;, WebKit::WebResourceLoader*, void (WebKit::WebResourceLoader::*)(double)) + 221 (HandleMessage.h:93)
14  com.apple.WebKit              	0x000000011cab157c WebKit::WebResourceLoader::didReceiveWebResourceLoaderMessage(IPC::Connection&amp;, IPC::MessageDecoder&amp;) + 636 (WebResourceLoaderMessageReceiver.cpp:68)
15  com.apple.WebKit              	0x000000011c3b8410 WebKit::NetworkProcessConnection::didReceiveMessage(IPC::Connection&amp;, IPC::MessageDecoder&amp;) + 160 (NetworkProcessConnection.cpp:62)
16  com.apple.WebKit              	0x000000011c16f023 IPC::Connection::dispatchMessage(IPC::MessageDecoder&amp;) + 51 (Connection.cpp:901)
17  com.apple.WebKit              	0x000000011c165f51 IPC::Connection::dispatchMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;) + 785 (Connection.cpp:933)
18  com.apple.WebKit              	0x000000011c16f61f IPC::Connection::dispatchOneMessage() + 1519 (Connection.cpp:962)
19  com.apple.WebKit              	0x000000011c18097d IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;)::$_10::operator()() const + 29 (Connection.cpp:895)
20  com.apple.WebKit              	0x000000011c18094d void std::__1::__invoke_void_return_wrapper&lt;void&gt;::__call&lt;IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;)::$_10&amp;&gt;(IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;)::$_10&amp;&amp;&amp;) + 45 (__functional_base:441)
21  com.apple.WebKit              	0x000000011c18079c std::__1::__function::__func&lt;IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;)::$_10, std::__1::allocator&lt;IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;)::$_10&gt;, void ()&gt;::operator()() + 44 (functional:1407)
22  com.apple.JavaScriptCore      	0x000000011f95368a std::__1::function&lt;void ()&gt;::operator()() const + 26 (functional:1793)
23  com.apple.JavaScriptCore      	0x000000011fef6fed WTF::RunLoop::performWork() + 621 (RunLoop.cpp:122)
24  com.apple.JavaScriptCore      	0x000000011fef75f4 WTF::RunLoop::performWork(void*) + 36 (RunLoopCF.cpp:38)
25  com.apple.CoreFoundation      	0x00007fff88dea621 __CFRUNLOOP_IS_CALLING_OUT_TO_A_SOURCE0_PERFORM_FUNCTION__ + 17
26  com.apple.CoreFoundation      	0x00007fff88dc9e1c __CFRunLoopDoSources0 + 556
27  com.apple.CoreFoundation      	0x00007fff88dc933f __CFRunLoopRun + 927
28  com.apple.CoreFoundation      	0x00007fff88dc8d38 CFRunLoopRunSpecific + 296
29  com.apple.HIToolbox           	0x00007fff83b01d55 RunCurrentEventLoopInMode + 235
30  com.apple.HIToolbox           	0x00007fff83b01b8f ReceiveNextEventCommon + 432
31  com.apple.HIToolbox           	0x00007fff83b019cf _BlockUntilNextEventMatchingListInModeWithFilter + 71
32  com.apple.AppKit              	0x00007fff8a645f3a _DPSNextEvent + 1067
33  com.apple.AppKit              	0x00007fff8a645369 -[NSApplication _nextEventMatchingEventMask:untilDate:inMode:dequeue:] + 454
34  com.apple.AppKit              	0x00007fff8a639ecc -[NSApplication run] + 682
35  com.apple.AppKit              	0x00007fff8a603162 NSApplicationMain + 1176
36  libxpc.dylib                  	0x00007fff970904f2 _xpc_objc_main + 793
37  libxpc.dylib                  	0x00007fff9708ef1e xpc_main + 494
38  com.apple.WebKit.WebContent.Development	0x000000010fca2be1 main + 785 (XPCServiceMain.Development.mm:187)
39  libdyld.dylib                 	0x00007fff84d425ad start + 1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1132928</commentid>
    <comment_count>6</comment_count>
    <who name="Jiewen Tan">jiewen_tan</who>
    <bug_when>2015-10-13 15:00:41 -0700</bug_when>
    <thetext>Please ignore the previous two comments.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1133242</commentid>
    <comment_count>7</comment_count>
      <attachid>262804</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2015-10-14 13:11:55 -0700</bug_when>
    <thetext>Comment on attachment 262804
Patch

Clearing flags on attachment: 262804

Committed r191066: &lt;http://trac.webkit.org/changeset/191066&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1133243</commentid>
    <comment_count>8</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2015-10-14 13:12:00 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>261434</attachid>
            <date>2015-09-17 14:56:36 -0700</date>
            <delta_ts>2015-09-17 14:56:36 -0700</delta_ts>
            <desc>crashing test</desc>
            <filename>insert-with-mutation-event.html</filename>
            <type>text/html</type>
            <size>706</size>
            <attacher name="Jon Honeycutt">jhoneycutt</attacher>
            
              <data encoding="base64">PCFET0NUWVBFIGh0bWw+Cjxib2R5Pgo8ZGl2IGlkPSJzYW1wbGUiIGNvbnRlbnRlZGl0YWJsZT0i
dHJ1ZSI+CmZvbwo8ZGl2IGlkPSJ0ZXN0IiBzdHlsZT0iZm9udC13ZWlnaHQ6Ym9sZCI+YmFyPC9k
aXY+CjwvZGl2Pgo8L2JvZHk+CjxzY3JpcHQ+CmlmICh3aW5kb3cudGVzdFJ1bm5lcikKICAgIHRl
c3RSdW5uZXIuZHVtcEFzVGV4dCgpOwpmdW5jdGlvbiAkKGlkKSB7IHJldHVybiBkb2N1bWVudC5n
ZXRFbGVtZW50QnlJZChpZCk7IH0Kd2luZG93LmdldFNlbGVjdGlvbigpLmNvbGxhcHNlKCQoJ3Rl
c3QnKSwgMCk7CmRvY3VtZW50LmV4ZWNDb21tYW5kKCdEZWxldGUnKTsKdmFyIHNhbXBsZSA9ICQo
J3NhbXBsZScpOwpzYW1wbGUuYWRkRXZlbnRMaXN0ZW5lcignRE9NU3VidHJlZU1vZGlmaWVkJywg
ZnVuY3Rpb24gKCkgewogICAgLy8gTW92ZSBub2RlcyBiZWluZyBwcm9jZXNzZWQgYnkgJ0luc2Vy
dFRleHQnIHRvIGFub3RoZXIgZG9jdW1lbnQuCiAgICB2YXIgYW5vdGhlckRvYyA9IGRvY3VtZW50
LmltcGxlbWVudGF0aW9uLmNyZWF0ZURvY3VtZW50KCcnLCBudWxsKTsKICAgIGFub3RoZXJEb2Mu
YWRvcHROb2RlKHNhbXBsZSk7Cn0pOwpkb2N1bWVudC5leGVjQ29tbWFuZCgnSW5zZXJ0VGV4dCcs
IGZhbHNlLCAnYWIxMjNjZCcpOwpkb2N1bWVudC5ib2R5LnRleHRDb250ZW50ID0gJ1BBU1M7IE5P
VCBDUkFTSEVEJzsKPC9zY3JpcHQ+Cg==
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>262804</attachid>
            <date>2015-10-09 17:24:31 -0700</date>
            <delta_ts>2015-10-14 13:11:55 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-149299-20151009172358.patch</filename>
            <type>text/plain</type>
            <size>3705</size>
            <attacher name="Jiewen Tan">jiewen_tan</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTkwODE4CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggZGViMjRlOGUxYmU4Nzcz
NmRjYjIxYTBiYmQ3Y2E2Y2YzNmI3NDljMy4uMGVmMWI4OWJmMWVkZTFkNzBjYWJmZTE2OWViODc5
YmQ2MTRlNDBjMSAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDE5IEBACisyMDE1LTEwLTA5ICBKaWV3
ZW4gVGFuICA8amlld2VuX3RhbkBhcHBsZS5jb20+CisKKyAgICAgICAgUG9zdHBvbmUgbXV0YXRp
b24gZXZlbnRzIGJlZm9yZSBpbnZva2UgRWRpdG9yOjpDb21tYW5kIGNvbW1hbmQoRG9jdW1lbnQq
LCBjb25zdCBTdHJpbmcmLCBib29sKS4KKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcv
c2hvd19idWcuY2dpP2lkPTE0OTI5OQorICAgICAgICA8cmRhcjovL3Byb2JsZW0vMjI3NDY5OTU+
CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAgICAgVGVzdDog
ZWRpdGluZy9pbnNlcnRpbmcvaW5zZXJ0LXdpdGgtbXV0YXRpb24tZXZlbnQuaHRtbAorCisgICAg
ICAgIFRoaXMgaXMgYSBtZXJnZSBvZiBhIHBhcnQgb2YgQmxpbmsgcjE2NjI5NDoKKyAgICAgICAg
aHR0cHM6Ly9jb2RlcmV2aWV3LmNocm9taXVtLm9yZy8xNDExMDMwMDYKKworICAgICAgICAqIGRv
bS9Eb2N1bWVudC5jcHA6CisgICAgICAgIChXZWJDb3JlOjpEb2N1bWVudDo6ZXhlY0NvbW1hbmQp
OgorCiAyMDE1LTEwLTA5ICBTaW1vbiBGcmFzZXIgIDxzaW1vbi5mcmFzZXJAYXBwbGUuY29tPgog
CiAgICAgICAgIEdhcmJhZ2UgcGl4ZWxzIG9uIGVucGhhc2VlbmVyZ3kuY29tIHNpdGUKZGlmZiAt
LWdpdCBhL1NvdXJjZS9XZWJDb3JlL2RvbS9Eb2N1bWVudC5jcHAgYi9Tb3VyY2UvV2ViQ29yZS9k
b20vRG9jdW1lbnQuY3BwCmluZGV4IDY5NGM5YzIyMzFjN2MzYTY4ODFhYWU5ZjFmYWRkZmM0MWY5
NjMzMzAuLmU5YmVkNTAwZTAyZTUwOWQ1ZmUwN2NlYTQ1ZWRiMTBjZDk2M2ZkOWMgMTAwNjQ0Ci0t
LSBhL1NvdXJjZS9XZWJDb3JlL2RvbS9Eb2N1bWVudC5jcHAKKysrIGIvU291cmNlL1dlYkNvcmUv
ZG9tL0RvY3VtZW50LmNwcApAQCAtNDY1Myw2ICs0NjUzLDcgQEAgc3RhdGljIEVkaXRvcjo6Q29t
bWFuZCBjb21tYW5kKERvY3VtZW50KiBkb2N1bWVudCwgY29uc3QgU3RyaW5nJiBjb21tYW5kTmFt
ZSwgYm8KIAogYm9vbCBEb2N1bWVudDo6ZXhlY0NvbW1hbmQoY29uc3QgU3RyaW5nJiBjb21tYW5k
TmFtZSwgYm9vbCB1c2VySW50ZXJmYWNlLCBjb25zdCBTdHJpbmcmIHZhbHVlKQogeworICAgIEV2
ZW50UXVldWVTY29wZSBldmVudFF1ZXVlU2NvcGU7CiAgICAgcmV0dXJuIGNvbW1hbmQodGhpcywg
Y29tbWFuZE5hbWUsIHVzZXJJbnRlcmZhY2UpLmV4ZWN1dGUodmFsdWUpOwogfQogCmRpZmYgLS1n
aXQgYS9MYXlvdXRUZXN0cy9DaGFuZ2VMb2cgYi9MYXlvdXRUZXN0cy9DaGFuZ2VMb2cKaW5kZXgg
MGU0YjhjNDdhODhiMDBlOTI3Njg5MTk2ZDg3MzI5YzBmYjI1NjMwYS4uNDlmMWY1NjNjZjQxMDNh
MDQ5NjY3NjhmYjg1ZjJhMDFkMTVkZDg2YiAxMDA2NDQKLS0tIGEvTGF5b3V0VGVzdHMvQ2hhbmdl
TG9nCisrKyBiL0xheW91dFRlc3RzL0NoYW5nZUxvZwpAQCAtMSwzICsxLDE0IEBACisyMDE1LTEw
LTA5ICBKaWV3ZW4gVGFuICA8amlld2VuX3RhbkBhcHBsZS5jb20+CisKKyAgICAgICAgUG9zdHBv
bmUgbXV0YXRpb24gZXZlbnRzIGJlZm9yZSBpbnZva2UgRWRpdG9yOjpDb21tYW5kIGNvbW1hbmQo
RG9jdW1lbnQqLCBjb25zdCBTdHJpbmcmLCBib29sKS4KKyAgICAgICAgaHR0cHM6Ly9idWdzLndl
YmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTE0OTI5OQorICAgICAgICA8cmRhcjovL3Byb2JsZW0v
MjI3NDY5OTU+CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAg
ICAgKiBlZGl0aW5nL2luc2VydGluZy9pbnNlcnQtd2l0aC1tdXRhdGlvbi1ldmVudC1leHBlY3Rl
ZC50eHQ6IEFkZGVkLgorICAgICAgICAqIGVkaXRpbmcvaW5zZXJ0aW5nL2luc2VydC13aXRoLW11
dGF0aW9uLWV2ZW50Lmh0bWw6IEFkZGVkLgorCiAyMDE1LTEwLTA5ICBTaW1vbiBGcmFzZXIgIDxz
aW1vbi5mcmFzZXJAYXBwbGUuY29tPgogCiAgICAgICAgIEdhcmJhZ2UgcGl4ZWxzIG9uIGVucGhh
c2VlbmVyZ3kuY29tIHNpdGUKZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL2VkaXRpbmcvaW5zZXJ0
aW5nL2luc2VydC13aXRoLW11dGF0aW9uLWV2ZW50LWV4cGVjdGVkLnR4dCBiL0xheW91dFRlc3Rz
L2VkaXRpbmcvaW5zZXJ0aW5nL2luc2VydC13aXRoLW11dGF0aW9uLWV2ZW50LWV4cGVjdGVkLnR4
dApuZXcgZmlsZSBtb2RlIDEwMDY0NAppbmRleCAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw
MDAwMDAwMDAwMDAwLi42NjE0NmI1YzI1ZTI1MWI5MjZkYTgyNDZmMjI3NmExNDE0NDAwOGY3Ci0t
LSAvZGV2L251bGwKKysrIGIvTGF5b3V0VGVzdHMvZWRpdGluZy9pbnNlcnRpbmcvaW5zZXJ0LXdp
dGgtbXV0YXRpb24tZXZlbnQtZXhwZWN0ZWQudHh0CkBAIC0wLDAgKzEgQEAKK1BBU1M7IE5PVCBD
UkFTSEVECmRpZmYgLS1naXQgYS9MYXlvdXRUZXN0cy9lZGl0aW5nL2luc2VydGluZy9pbnNlcnQt
d2l0aC1tdXRhdGlvbi1ldmVudC5odG1sIGIvTGF5b3V0VGVzdHMvZWRpdGluZy9pbnNlcnRpbmcv
aW5zZXJ0LXdpdGgtbXV0YXRpb24tZXZlbnQuaHRtbApuZXcgZmlsZSBtb2RlIDEwMDY0NAppbmRl
eCAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwLi5lNGM1ZDk3MTc0YjNm
YTI4MDY2NTllNGM4ZTY1YTQyNTdhN2NmNjg4Ci0tLSAvZGV2L251bGwKKysrIGIvTGF5b3V0VGVz
dHMvZWRpdGluZy9pbnNlcnRpbmcvaW5zZXJ0LXdpdGgtbXV0YXRpb24tZXZlbnQuaHRtbApAQCAt
MCwwICsxLDIyIEBACis8IURPQ1RZUEUgaHRtbD4KKzxib2R5PgorPGRpdiBpZD0ic2FtcGxlIiBj
b250ZW50ZWRpdGFibGU9InRydWUiPgorZm9vCis8ZGl2IGlkPSJ0ZXN0IiBzdHlsZT0iZm9udC13
ZWlnaHQ6Ym9sZCI+YmFyPC9kaXY+Cis8L2Rpdj4KKzwvYm9keT4KKzxzY3JpcHQ+CitpZiAod2lu
ZG93LnRlc3RSdW5uZXIpCisgICAgdGVzdFJ1bm5lci5kdW1wQXNUZXh0KCk7CitmdW5jdGlvbiAk
KGlkKSB7IHJldHVybiBkb2N1bWVudC5nZXRFbGVtZW50QnlJZChpZCk7IH0KK3dpbmRvdy5nZXRT
ZWxlY3Rpb24oKS5jb2xsYXBzZSgkKCd0ZXN0JyksIDApOworZG9jdW1lbnQuZXhlY0NvbW1hbmQo
J0RlbGV0ZScpOwordmFyIHNhbXBsZSA9ICQoJ3NhbXBsZScpOworc2FtcGxlLmFkZEV2ZW50TGlz
dGVuZXIoJ0RPTVN1YnRyZWVNb2RpZmllZCcsIGZ1bmN0aW9uICgpIHsKKyAgICAvLyBNb3ZlIG5v
ZGVzIGJlaW5nIHByb2Nlc3NlZCBieSAnSW5zZXJ0VGV4dCcgdG8gYW5vdGhlciBkb2N1bWVudC4K
KyAgICB2YXIgYW5vdGhlckRvYyA9IGRvY3VtZW50LmltcGxlbWVudGF0aW9uLmNyZWF0ZURvY3Vt
ZW50KCcnLCBudWxsKTsKKyAgICBhbm90aGVyRG9jLmFkb3B0Tm9kZShzYW1wbGUpOworfSk7Citk
b2N1bWVudC5leGVjQ29tbWFuZCgnSW5zZXJ0VGV4dCcsIGZhbHNlLCAnYWIxMjNjZCcpOworZG9j
dW1lbnQuYm9keS50ZXh0Q29udGVudCA9ICdQQVNTOyBOT1QgQ1JBU0hFRCc7Cis8L3NjcmlwdD4K
</data>

          </attachment>
      

    </bug>

</bugzilla>