<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>149316</bug_id>
          
          <creation_ts>2015-09-17 16:45:07 -0700</creation_ts>
          <short_desc>Null dereference loading Blink layout test svg/filters/feImage-failed-load-crash.html</short_desc>
          <delta_ts>2015-09-19 03:00:21 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>SVG</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>BlinkMergeCandidate, HasReduction, InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Jon Honeycutt">jhoneycutt</reporter>
          <assigned_to name="Dean Jackson">dino</assigned_to>
          <cc>dino</cc>
    
    <cc>webkit-bug-importer</cc>
    
    <cc>zimmermann</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1126933</commentid>
    <comment_count>0</comment_count>
      <attachid>261454</attachid>
    <who name="Jon Honeycutt">jhoneycutt</who>
    <bug_when>2015-09-17 16:45:07 -0700</bug_when>
    <thetext>Created attachment 261454
crashing test

Null dereference loading Blink layout test svg/filters/feImage-failed-load-crash.html.

Stack trace:

Crashed Thread:        0  Dispatch queue: com.apple.main-thread

Exception Type:        EXC_BAD_ACCESS (SIGSEGV)
Exception Codes:       KERN_INVALID_ADDRESS at 0x0000000000000014
Exception Note:        EXC_CORPSE_NOTIFY

VM Regions Near 0x14:
--&gt; 
    __TEXT                 00000001065fe000-0000000106600000 [    8K] r-x/rwx SM=COW  /Users/USER/*/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.Development.xpc/Contents/MacOS/com.apple.WebKit.WebContent.Development

Application Specific Information:
CRASHING TEST: temp-tests/svg/filters/feImage-failed-load-crash.html

Global Trace Buffer (reverse chronological seconds):
18446743971.992725 CFNetwork                 	0x00007fff88d43b97 Explicitly setting CF cookie storage singleton
18446743971.993103 CFNetwork                 	0x00007fff88d8f211 Explicitly setting cookie storage singleton

Thread 0 Crashed:: Dispatch queue: com.apple.main-thread
0   com.apple.WebCore             	0x000000010f16e585 non-virtual thunk to WebCore::SVGFEImageElement::notifyFinished(WebCore::CachedResource*) + 37 (Node.h:638)
1   com.apple.WebCore             	0x000000010e3b8179 WebCore::CachedResource::checkNotify() + 153 (CachedResourceClientWalker.h:51)
2   com.apple.WebCore             	0x000000010e3b2a91 WebCore::CachedImage::error(WebCore::CachedResource::Status) + 113 (CachedImage.cpp:443)
3   com.apple.WebCore             	0x000000010f12f807 WebCore::SubresourceLoader::didFail(WebCore::ResourceError const&amp;) + 375 (SubresourceLoader.cpp:401)
4   com.apple.WebKit              	0x000000010cc75d35 void IPC::handleMessage&lt;Messages::WebResourceLoader::DidFailResourceLoad, WebKit::WebResourceLoader, void (WebKit::WebResourceLoader::*)(WebCore::ResourceError const&amp;)&gt;(IPC::MessageDecoder&amp;, WebKit::WebResourceLoader*, void (WebKit::WebResourceLoader::*)(WebCore::ResourceError const&amp;)) + 100 (StdLibExtras.h:366)
5   com.apple.WebKit              	0x000000010ca4f1f1 IPC::Connection::dispatchMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;) + 127 (memory:2636)
6   com.apple.WebKit              	0x000000010ca51b4a IPC::Connection::dispatchOneMessage() + 126 (memory:2656)
7   com.apple.JavaScriptCore      	0x000000010de93985 WTF::RunLoop::performWork() + 437 (functional:1742)
8   com.apple.JavaScriptCore      	0x000000010de93d32 WTF::RunLoop::performWork(void*) + 34 (RunLoopCF.cpp:39)
9   com.apple.CoreFoundation      	0x00007fff949e2c01 __CFRUNLOOP_IS_CALLING_OUT_TO_A_SOURCE0_PERFORM_FUNCTION__ + 17
10  com.apple.CoreFoundation      	0x00007fff949d4b1c __CFRunLoopDoSources0 + 556
11  com.apple.CoreFoundation      	0x00007fff949d403f __CFRunLoopRun + 927
12  com.apple.CoreFoundation      	0x00007fff949d3a38 CFRunLoopRunSpecific + 296
13  com.apple.HIToolbox           	0x00007fff88e673bd RunCurrentEventLoopInMode + 235
14  com.apple.HIToolbox           	0x00007fff88e67153 ReceiveNextEventCommon + 432
15  com.apple.HIToolbox           	0x00007fff88e66f93 _BlockUntilNextEventMatchingListInModeWithFilter + 71
16  com.apple.AppKit              	0x00007fff870b81e7 _DPSNextEvent + 1076
17  com.apple.AppKit              	0x00007fff8748490d -[NSApplication _nextEventMatchingEventMask:untilDate:inMode:dequeue:] + 454
18  com.apple.AppKit              	0x00007fff870ae0b8 -[NSApplication run] + 682
19  com.apple.AppKit              	0x00007fff87030396 NSApplicationMain + 1176
20  libxpc.dylib                  	0x00007fff8c70ff70 _xpc_objc_main + 793
21  libxpc.dylib                  	0x00007fff8c7116bf xpc_main + 494
22  com.apple.WebKit.WebContent.Development	0x00000001065ff424 main + 409 (XPCServiceMain.Development.mm:187)
23  libdyld.dylib                 	0x00007fff93aa15ad start + 1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1126935</commentid>
    <comment_count>1</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2015-09-17 16:46:03 -0700</bug_when>
    <thetext>&lt;rdar://problem/22749532&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1127337</commentid>
    <comment_count>2</comment_count>
      <attachid>261559</attachid>
    <who name="Dean Jackson">dino</who>
    <bug_when>2015-09-18 18:58:54 -0700</bug_when>
    <thetext>Created attachment 261559
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1127381</commentid>
    <comment_count>3</comment_count>
    <who name="Dean Jackson">dino</who>
    <bug_when>2015-09-19 03:00:21 -0700</bug_when>
    <thetext>Committed r190013: &lt;http://trac.webkit.org/changeset/190013&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>261454</attachid>
            <date>2015-09-17 16:45:07 -0700</date>
            <delta_ts>2015-09-17 16:45:07 -0700</delta_ts>
            <desc>crashing test</desc>
            <filename>feImage-failed-load-crash.html</filename>
            <type>text/html</type>
            <size>558</size>
            <attacher name="Jon Honeycutt">jhoneycutt</attacher>
            
              <data encoding="base64">PCFET0NUWVBFIEhUTUw+CjxodG1sPgo8Ym9keT4KICAgIFRlc3QgZm9yIGNyYnVnLmNvbS80NjEx
NTE6IFRoaXMgdGVzdCBwYXNzZXMgaWYgaXQgZG9lcyBub3QgY3Jhc2guCiAgICA8c3ZnPgogICAg
ICAgIDxmZUltYWdlIGlkPSJmZUltYWdlIj48L2ZlSW1hZ2U+CiAgICA8L3N2Zz4KICAgIDxzY3Jp
cHQ+CiAgICAgICAgb25sb2FkID0gZnVuY3Rpb24oKSB7CiAgICAgICAgICAgIGlmICh3aW5kb3cu
dGVzdFJ1bm5lcikKICAgICAgICAgICAgICAgIHRlc3RSdW5uZXIuZHVtcEFzVGV4dCgpOwogICAg
ICAgICAgICBmZUltYWdlLnNldEF0dHJpYnV0ZU5TKCdodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs
aW5rJywgJ3hsaW5rOmhyZWYnLCAnI2RvZXNub3RleGlzdCcpOwogICAgICAgICAgICBkb2N1bWVu
dC5yZXBsYWNlQ2hpbGQoZmVJbWFnZSwgZG9jdW1lbnQuZG9jdW1lbnRFbGVtZW50KTsKICAgICAg
ICAgICAgZmVJbWFnZS5zZXRBdHRyaWJ1dGUoInhsaW5rOmhyZWYiLCAiZG9lc25vdGV4aXN0LnN2
ZyIpOwogICAgICAgIH0KICAgIDwvc2NyaXB0Pgo8L2JvZHk+CjwvaHRtbD4K
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>261559</attachid>
            <date>2015-09-18 18:58:54 -0700</date>
            <delta_ts>2015-09-18 21:27:12 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-149316-20150919115839.patch</filename>
            <type>text/plain</type>
            <size>4019</size>
            <attacher name="Dean Jackson">dino</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTg5OTg5CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggODQ5MzMxOWJlMDQxZjEw
NzRkOWNkZjIxMzdiNDY2ZDM5MmJiMzc2Ni4uNTU4MzEyNTVhODVlZDlhYzUyZDM0ZmVhOWNhMjli
MThjZDcwMDQ1MSAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDIzIEBACisyMDE1LTA5LTE4ICBEZWFu
IEphY2tzb24gIDxkaW5vQGFwcGxlLmNvbT4KKworICAgICAgICBOdWxsIGRlcmVmZXJlbmNlIGxv
YWRpbmcgQmxpbmsgbGF5b3V0IHRlc3Qgc3ZnL2ZpbHRlcnMvZmVJbWFnZS1mYWlsZWQtbG9hZC1j
cmFzaC5odG1sCisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9p
ZD0xNDkzMTYKKyAgICAgICAgPHJkYXI6Ly9wcm9ibGVtLzIyNzQ5NTMyPgorCisgICAgICAgIFJl
dmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIElmIGFuIGZlSW1hZ2UgdHJpZ2dl
cmVkIGxvYWRpbmcgYSByZXNvdXJjZSwgYW5kIHRoZW4gd2FzIHJlbW92ZWQgZnJvbSB0aGUgZG9j
dW1lbnQsCisgICAgICAgIHdlJ2Qgc3RpbGwgdHJ5IHRvIG5vdGlmeSBpdHMgcGFyZW50IHdoZW4g
dGhlIHJlc291cmNlIGFycml2ZWQgKG9yIGZhaWxlZCkuCisKKyAgICAgICAgTWVyZ2UgQmxpbmsg
Y29tbWl0OgorICAgICAgICBodHRwczovL2Nocm9taXVtLmdvb2dsZXNvdXJjZS5jb20vY2hyb21p
dW0vYmxpbmsvKy85Y2JjZmQ3ODY2YmJhZmYwYzRiM2M0Yzg1MDhiN2M5N2I0NmQ2ZTZhCisKKyAg
ICAgICAgVGVzdDogc3ZnL2ZpbHRlcnMvZmVJbWFnZS1mYWlsZWQtbG9hZC1jcmFzaC5odG1sCisK
KyAgICAgICAgKiBzdmcvU1ZHRkVJbWFnZUVsZW1lbnQuY3BwOgorICAgICAgICAoV2ViQ29yZTo6
U1ZHRkVJbWFnZUVsZW1lbnQ6Om5vdGlmeUZpbmlzaGVkKTogQWRkIGEgbnVsbCBjaGVjayB0byB0
aGUgcGFyZW50IGVsZW1lbnQKKyAgICAgICAgYmVmb3JlIHNlbmRpbmcgdGhlIG5vdGlmaWNhdGlv
bi4KKwogMjAxNS0wOS0xOCAgQWxleCBDaHJpc3RlbnNlbiAgPGFjaHJpc3RlbnNlbkB3ZWJraXQu
b3JnPgogCiAgICAgICAgIENNYWtlIGNsZWFuIGJ1aWxkIGZpeCBhZnRlciByMTg5OTcxLgpkaWZm
IC0tZ2l0IGEvU291cmNlL1dlYkNvcmUvc3ZnL1NWR0ZFSW1hZ2VFbGVtZW50LmNwcCBiL1NvdXJj
ZS9XZWJDb3JlL3N2Zy9TVkdGRUltYWdlRWxlbWVudC5jcHAKaW5kZXggZmZmYzNkOGFmZGI5ODgz
YzU0N2MxMzJmNTA2ZjhmNGZlODFjNGE4MC4uNTkyZGNiNjk0MzFmNzMxYzA4NzhlYTM0Y2RkYTFi
MTFmZmM1YjZhNyAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvc3ZnL1NWR0ZFSW1hZ2VFbGVt
ZW50LmNwcAorKysgYi9Tb3VyY2UvV2ViQ29yZS9zdmcvU1ZHRkVJbWFnZUVsZW1lbnQuY3BwCkBA
IC0xNjcsOSArMTY3LDggQEAgdm9pZCBTVkdGRUltYWdlRWxlbWVudDo6bm90aWZ5RmluaXNoZWQo
Q2FjaGVkUmVzb3VyY2UqKQogICAgICAgICByZXR1cm47CiAKICAgICBFbGVtZW50KiBwYXJlbnQg
PSBwYXJlbnRFbGVtZW50KCk7Ci0gICAgQVNTRVJUKHBhcmVudCk7CiAKLSAgICBpZiAoIXBhcmVu
dC0+aGFzVGFnTmFtZShTVkdOYW1lczo6ZmlsdGVyVGFnKSkKKyAgICBpZiAoIXBhcmVudCB8fCAh
cGFyZW50LT5oYXNUYWdOYW1lKFNWR05hbWVzOjpmaWx0ZXJUYWcpKQogICAgICAgICByZXR1cm47
CiAKICAgICBSZW5kZXJFbGVtZW50KiBwYXJlbnRSZW5kZXJlciA9IHBhcmVudC0+cmVuZGVyZXIo
KTsKZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL0NoYW5nZUxvZyBiL0xheW91dFRlc3RzL0NoYW5n
ZUxvZwppbmRleCBiNmFjMTFjNTI1MTcxNTRlMjRiZDA1MmIyMjhkMTA4M2U5OTdmY2I1Li43Y2Y5
ZTcwOWQwZmI1ZTA3Yzg3NWJjZmUyYzEwNjBmZTJhZDBiYWIwIDEwMDY0NAotLS0gYS9MYXlvdXRU
ZXN0cy9DaGFuZ2VMb2cKKysrIGIvTGF5b3V0VGVzdHMvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTYg
QEAKKzIwMTUtMDktMTggIERlYW4gSmFja3NvbiAgPGRpbm9AYXBwbGUuY29tPgorCisgICAgICAg
IE51bGwgZGVyZWZlcmVuY2UgbG9hZGluZyBCbGluayBsYXlvdXQgdGVzdCBzdmcvZmlsdGVycy9m
ZUltYWdlLWZhaWxlZC1sb2FkLWNyYXNoLmh0bWwKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtp
dC5vcmcvc2hvd19idWcuY2dpP2lkPTE0OTMxNgorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9E
WSAoT09QUyEpLgorCisgICAgICAgIE1lcmdlIEJsaW5rIGNvbW1pdDoKKyAgICAgICAgaHR0cHM6
Ly9jaHJvbWl1bS5nb29nbGVzb3VyY2UuY29tL2Nocm9taXVtL2JsaW5rLysvOWNiY2ZkNzg2NmJi
YWZmMGM0YjNjNGM4NTA4YjdjOTdiNDZkNmU2YQorCisgICAgICAgICogc3ZnL2ZpbHRlcnMvZmVJ
bWFnZS1mYWlsZWQtbG9hZC1jcmFzaC1leHBlY3RlZC50eHQ6IEFkZGVkLgorICAgICAgICAqIHN2
Zy9maWx0ZXJzL2ZlSW1hZ2UtZmFpbGVkLWxvYWQtY3Jhc2guaHRtbDogQWRkZWQuCisKIDIwMTUt
MDktMTggIEpha2UgTmllbHNlbiAgPGphY29iX25pZWxzZW5AYXBwbGUuY29tPgogCiAgICAgICAg
IFJFR1JFU1NJT046IGh0dHAvdGVzdHMveG1saHR0cHJlcXVlc3QvdGltZW91dC94bWxodHRwcmVx
dWVzdC10aW1lb3V0LW92ZXJyaWRlcy5odG1sIGlzIGZsYWt5CmRpZmYgLS1naXQgYS9MYXlvdXRU
ZXN0cy9zdmcvZmlsdGVycy9mZUltYWdlLWZhaWxlZC1sb2FkLWNyYXNoLWV4cGVjdGVkLnR4dCBi
L0xheW91dFRlc3RzL3N2Zy9maWx0ZXJzL2ZlSW1hZ2UtZmFpbGVkLWxvYWQtY3Jhc2gtZXhwZWN0
ZWQudHh0Cm5ldyBmaWxlIG1vZGUgMTAwNjQ0CmluZGV4IDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw
MDAwMDAwMDAwMDAwMDAwMDAuLjhiMTM3ODkxNzkxZmU5NjkyN2FkNzhlNjRiMGFhZDdiZGVkMDhi
ZGMKLS0tIC9kZXYvbnVsbAorKysgYi9MYXlvdXRUZXN0cy9zdmcvZmlsdGVycy9mZUltYWdlLWZh
aWxlZC1sb2FkLWNyYXNoLWV4cGVjdGVkLnR4dApAQCAtMCwwICsxIEBACisKZGlmZiAtLWdpdCBh
L0xheW91dFRlc3RzL3N2Zy9maWx0ZXJzL2ZlSW1hZ2UtZmFpbGVkLWxvYWQtY3Jhc2guaHRtbCBi
L0xheW91dFRlc3RzL3N2Zy9maWx0ZXJzL2ZlSW1hZ2UtZmFpbGVkLWxvYWQtY3Jhc2guaHRtbApu
ZXcgZmlsZSBtb2RlIDEwMDY0NAppbmRleCAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw
MDAwMDAwMDAwLi4zZmQxNDE0MThhMzdmNWQxZWMwYjc2MTZiOTZiOWI3ZTY2YmZjNDE2Ci0tLSAv
ZGV2L251bGwKKysrIGIvTGF5b3V0VGVzdHMvc3ZnL2ZpbHRlcnMvZmVJbWFnZS1mYWlsZWQtbG9h
ZC1jcmFzaC5odG1sCkBAIC0wLDAgKzEsMTkgQEAKKzwhRE9DVFlQRSBIVE1MPgorPGh0bWw+Cis8
Ym9keT4KKyAgICA8cCBpZD0iYSI+VGhpcyB0ZXN0IHBhc3NlcyBpZiBpdCBkb2VzIG5vdCBjcmFz
aC48L3A+CisgICAgPHN2Zz4KKyAgICAgICAgPGZlSW1hZ2UgaWQ9ImZlSW1hZ2UiPjwvZmVJbWFn
ZT4KKyAgICA8L3N2Zz4KKyAgICA8c2NyaXB0PgorICAgICAgICBvbmxvYWQgPSBmdW5jdGlvbigp
IHsKKyAgICAgICAgICAgIGlmICh3aW5kb3cudGVzdFJ1bm5lcikKKyAgICAgICAgICAgICAgICB0
ZXN0UnVubmVyLmR1bXBBc1RleHQoKTsKKyAgICAgICAgICAgIHZhciBmZUltYWdlID0gZG9jdW1l
bnQuZ2V0RWxlbWVudEJ5SWQoImZlSW1hZ2UiKTsKKyAgICAgICAgICAgIGZlSW1hZ2Uuc2V0QXR0
cmlidXRlTlMoImh0dHA6Ly93d3cudzMub3JnLzE5OTkveGxpbmsiLCAieGxpbms6aHJlZiIsICIj
ZG9lc25vdGV4aXN0Iik7CisgICAgICAgICAgICBkb2N1bWVudC5yZXBsYWNlQ2hpbGQoZmVJbWFn
ZSwgZG9jdW1lbnQuZG9jdW1lbnRFbGVtZW50KTsKKyAgICAgICAgICAgIGZlSW1hZ2Uuc2V0QXR0
cmlidXRlKCJ4bGluazpocmVmIiwgImRvZXNub3RleGlzdC5zdmciKTsKKyAgICAgICAgfQorICAg
IDwvc2NyaXB0PgorPC9ib2R5PgorPC9odG1sPgo=
</data>
<flag name="review"
          id="286748"
          type_id="1"
          status="+"
          setter="thorton"
    />
          </attachment>
      

    </bug>

</bugzilla>