<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>155642</bug_id>
          
          <creation_ts>2016-03-18 09:16:38 -0700</creation_ts>
          <short_desc>SEGV in WebCore::RenderTableCell::setCol</short_desc>
          <delta_ts>2016-03-21 16:30:05 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Layout and Rendering</component>
          <version>WebKit Local Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>116980</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="Renata Hodovan">rhodovan.u-szeged</reporter>
          <assigned_to name="alan">zalan</assigned_to>
          <cc>ap</cc>
    
    <cc>commit-queue</cc>
    
    <cc>esprehn+autocc</cc>
    
    <cc>glenn</cc>
    
    <cc>kling</cc>
    
    <cc>kondapallykalyan</cc>
    
    <cc>simon.fraser</cc>
    
    <cc>zalan</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1176184</commentid>
    <comment_count>0</comment_count>
      <attachid>274419</attachid>
    <who name="Renata Hodovan">rhodovan.u-szeged</who>
    <bug_when>2016-03-18 09:16:38 -0700</bug_when>
    <thetext>Created attachment 274419
Test case

Load the attached test with minibrowser:

&lt;!DOCTYPE html&gt;
&lt;table&gt;
    &lt;td colspan=&quot;53927142&quot;&gt;&lt;/td&gt;
    &lt;th&gt;
        &lt;td&gt;&lt;/td&gt;
    &lt;/th&gt;
&lt;/table&gt;


OS: Mac OS X 10.11.1 (x86_64), x86_64
Checked build: ASAN debug
Checked version: 5e169ea


Backtrace:

1   0x114f8f0d4 WTFCrash
2   0x11de0307c WebCore::RenderTableCell::setCol(unsigned int)
3   0x11dde57ca WebCore::RenderTableSection::addCell(WebCore::RenderTableCell*, WebCore::RenderTableRow*)
4   0x11dde12c8 WebCore::RenderTableRow::addChild(WebCore::RenderObject*, WebCore::RenderObject*)
5   0x11e938c1a WebCore::RenderTreePosition::insert(WebCore::RenderObject&amp;)
6   0x11e92d0b6 WebCore::Style::TreeResolver::createRenderer(WebCore::Element&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;)
7   0x11e92e0aa WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;)
8   0x11e92daaf WebCore::Style::TreeResolver::createRenderTreeForChildren(WebCore::ContainerNode&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;)
9   0x11e92e204 WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;)
10  0x11e92daaf WebCore::Style::TreeResolver::createRenderTreeForChildren(WebCore::ContainerNode&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;)
11  0x11e92e204 WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;)
12  0x11e92daaf WebCore::Style::TreeResolver::createRenderTreeForChildren(WebCore::ContainerNode&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;)
13  0x11e92e204 WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;)
14  0x11e92daaf WebCore::Style::TreeResolver::createRenderTreeForChildren(WebCore::ContainerNode&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;)
15  0x11e92e204 WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;)
16  0x11e92daaf WebCore::Style::TreeResolver::createRenderTreeForChildren(WebCore::ContainerNode&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;)
17  0x11e92e204 WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;)
18  0x11e92f7e9 WebCore::Style::TreeResolver::resolveElement(WebCore::Element&amp;)
19  0x11e9319f6 WebCore::Style::TreeResolver::resolveComposedTree()
20  0x11e93220c WebCore::Style::TreeResolver::resolve(WebCore::Style::Change)
21  0x119d97665 WebCore::Document::recalcStyle(WebCore::Style::Change)
22  0x119d8124b WebCore::Document::updateStyleIfNeeded()
23  0x119dbb961 WebCore::Document::finishedParsing()
24  0x11ab76e96 WebCore::HTMLConstructionSite::finishedParsing()
25  0x11aea743c WebCore::HTMLTreeBuilder::finished()
26  0x11abebb8c WebCore::HTMLDocumentParser::end()
27  0x11abe7d9a WebCore::HTMLDocumentParser::attemptToRunDeferredScriptsAndEnd()
28  0x11abe7a09 WebCore::HTMLDocumentParser::prepareToStopParsing()
29  0x11abebc2e WebCore::HTMLDocumentParser::attemptToEnd()
30  0x11abebc88 WebCore::HTMLDocumentParser::finish()
31  0x119f775e0 WebCore::DocumentWriter::end()
ASAN:SIGSEGV
=================================================================
==82191==ERROR: AddressSanitizer: SEGV on unknown address 0x0000bbadbeef (pc 0x000114f8f10c bp 0x7fff53d407f0 sp 0x7fff53d407e0 T0)
    #0 0x114f8f10b in WTFCrash (/Users/reni/work/WebKit/WebKitBuild/Debug/JavaScriptCore.framework/Versions/A/JavaScriptCore+0x2b2110b)
    #1 0x11de0307b in WebCore::RenderTableCell::setCol(unsigned int) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x517a07b)
    #2 0x11dde57c9 in WebCore::RenderTableSection::addCell(WebCore::RenderTableCell*, WebCore::RenderTableRow*) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x515c7c9)
    #3 0x11dde12c7 in WebCore::RenderTableRow::addChild(WebCore::RenderObject*, WebCore::RenderObject*) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x51582c7)
    #4 0x11e938c19 in WebCore::RenderTreePosition::insert(WebCore::RenderObject&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5cafc19)
    #5 0x11e92d0b5 in WebCore::Style::TreeResolver::createRenderer(WebCore::Element&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca40b5)
    #6 0x11e92e0a9 in WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca50a9)
    #7 0x11e92daae in WebCore::Style::TreeResolver::createRenderTreeForChildren(WebCore::ContainerNode&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca4aae)
    #8 0x11e92e203 in WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca5203)
    #9 0x11e92daae in WebCore::Style::TreeResolver::createRenderTreeForChildren(WebCore::ContainerNode&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca4aae)
    #10 0x11e92e203 in WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca5203)
    #11 0x11e92daae in WebCore::Style::TreeResolver::createRenderTreeForChildren(WebCore::ContainerNode&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca4aae)
    #12 0x11e92e203 in WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca5203)
    #13 0x11e92daae in WebCore::Style::TreeResolver::createRenderTreeForChildren(WebCore::ContainerNode&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca4aae)
    #14 0x11e92e203 in WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca5203)
    #15 0x11e92daae in WebCore::Style::TreeResolver::createRenderTreeForChildren(WebCore::ContainerNode&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca4aae)
    #16 0x11e92e203 in WebCore::Style::TreeResolver::createRenderTreeRecursively(WebCore::Element&amp;, WebCore::RenderStyle&amp;, WebCore::RenderTreePosition&amp;, WTF::RefPtr&lt;WebCore::RenderStyle&gt;&amp;&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca5203)
    #17 0x11e92f7e8 in WebCore::Style::TreeResolver::resolveElement(WebCore::Element&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca67e8)
    #18 0x11e9319f5 in WebCore::Style::TreeResolver::resolveComposedTree() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca89f5)
    #19 0x11e93220b in WebCore::Style::TreeResolver::resolve(WebCore::Style::Change) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5ca920b)
    #20 0x119d97664 in WebCore::Document::recalcStyle(WebCore::Style::Change) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x110e664)
    #21 0x119d8124a in WebCore::Document::updateStyleIfNeeded() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x10f824a)
    #22 0x119dbb960 in WebCore::Document::finishedParsing() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x1132960)
    #23 0x11ab76e95 in WebCore::HTMLConstructionSite::finishedParsing() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x1eede95)
    #24 0x11aea743b in WebCore::HTMLTreeBuilder::finished() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x221e43b)
    #25 0x11abebb8b in WebCore::HTMLDocumentParser::end() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x1f62b8b)
    #26 0x11abe7d99 in WebCore::HTMLDocumentParser::attemptToRunDeferredScriptsAndEnd() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x1f5ed99)
    #27 0x11abe7a08 in WebCore::HTMLDocumentParser::prepareToStopParsing() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x1f5ea08)
    #28 0x11abebc2d in WebCore::HTMLDocumentParser::attemptToEnd() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x1f62c2d)
    #29 0x11abebc87 in WebCore::HTMLDocumentParser::finish() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x1f62c87)
    #30 0x119f775df in WebCore::DocumentWriter::end() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x12ee5df)
    #31 0x119ec9a5c in WebCore::DocumentLoader::finishedLoading(double) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x1240a5c)
    #32 0x119ec956a in WebCore::DocumentLoader::notifyFinished(WebCore::CachedResource*) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x124056a)
    #33 0x1192a1e66 in WebCore::CachedResource::checkNotify() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x618e66)
    #34 0x1192a2053 in WebCore::CachedResource::finishLoading(WebCore::SharedBuffer*) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x619053)
    #35 0x1192983cc in WebCore::CachedRawResource::finishLoading(WebCore::SharedBuffer*) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x60f3cc)
    #36 0x11e95dd20 in WebCore::SubresourceLoader::didFinishLoading(double) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebCore.framework/Versions/A/WebCore+0x5cd4d20)
    #37 0x10d9e415c in WebKit::WebResourceLoader::didFinishResourceLoad(double) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x1b1315c)
    #38 0x10d9f84f2 in void IPC::callMemberFunctionImpl&lt;WebKit::WebResourceLoader, void (WebKit::WebResourceLoader::*)(double), std::__1::tuple&lt;double&gt;, 0ul&gt;(WebKit::WebResourceLoader*, void (WebKit::WebResourceLoader::*)(double), std::__1::tuple&lt;double&gt;&amp;&amp;, std::index_sequence&lt;0ul&gt;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x1b274f2)
    #39 0x10d9f8171 in void IPC::callMemberFunction&lt;WebKit::WebResourceLoader, void (WebKit::WebResourceLoader::*)(double), std::__1::tuple&lt;double&gt;, std::make_index_sequence&lt;1ul&gt; &gt;(std::__1::tuple&lt;double&gt;&amp;&amp;, WebKit::WebResourceLoader*, void (WebKit::WebResourceLoader::*)(double)) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x1b27171)
    #40 0x10d9f452e in void IPC::handleMessage&lt;Messages::WebResourceLoader::DidFinishResourceLoad, WebKit::WebResourceLoader, void (WebKit::WebResourceLoader::*)(double)&gt;(IPC::MessageDecoder&amp;, WebKit::WebResourceLoader*, void (WebKit::WebResourceLoader::*)(double)) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x1b2352e)
    #41 0x10d9f15ad in WebKit::WebResourceLoader::didReceiveWebResourceLoaderMessage(IPC::Connection&amp;, IPC::MessageDecoder&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x1b205ad)
    #42 0x10c7674f2 in WebKit::NetworkProcessConnection::didReceiveMessage(IPC::Connection&amp;, IPC::MessageDecoder&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x8964f2)
    #43 0x10c0a4fa0 in IPC::Connection::dispatchMessage(IPC::MessageDecoder&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x1d3fa0)
    #44 0x10c08c501 in IPC::Connection::dispatchMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x1bb501)
    #45 0x10c0a5d90 in IPC::Connection::dispatchOneMessage() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x1d4d90)
    #46 0x10c0d54dc in IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;)::$_10::operator()() const (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x2044dc)
    #47 0x10c0d54ac in void std::__1::__invoke_void_return_wrapper&lt;void&gt;::__call&lt;IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;)::$_10&amp;&gt;(IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;)::$_10&amp;&amp;&amp;) (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x2044ac)
    #48 0x10c0d52cb in std::__1::__function::__func&lt;IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;)::$_10, std::__1::allocator&lt;IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::MessageDecoder, std::__1::default_delete&lt;IPC::MessageDecoder&gt; &gt;)::$_10&gt;, void ()&gt;::operator()() (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/WebKit+0x2042cb)
    #49 0x113dc79fa in std::__1::function&lt;void ()&gt;::operator()() const (/Users/reni/work/WebKit/WebKitBuild/Debug/JavaScriptCore.framework/Versions/A/JavaScriptCore+0x19599fa)
    #50 0x1150698dd in WTF::RunLoop::performWork() (/Users/reni/work/WebKit/WebKitBuild/Debug/JavaScriptCore.framework/Versions/A/JavaScriptCore+0x2bfb8dd)
    #51 0x11506a849 in WTF::RunLoop::performWork(void*) (/Users/reni/work/WebKit/WebKitBuild/Debug/JavaScriptCore.framework/Versions/A/JavaScriptCore+0x2bfc849)
    #52 0x7fff888498b0 in __CFRUNLOOP_IS_CALLING_OUT_TO_A_SOURCE0_PERFORM_FUNCTION__ (/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation+0xaa8b0)
    #53 0x7fff888290ab in __CFRunLoopDoSources0 (/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation+0x8a0ab)
    #54 0x7fff888285ce in __CFRunLoopRun (/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation+0x895ce)
    #55 0x7fff88827fc7 in CFRunLoopRunSpecific (/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation+0x88fc7)
    #56 0x7fff86540d54 in RunCurrentEventLoopInMode (/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.framework/Versions/A/HIToolbox+0x30d54)
    #57 0x7fff86540b8e in ReceiveNextEventCommon (/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.framework/Versions/A/HIToolbox+0x30b8e)
    #58 0x7fff865409ce in _BlockUntilNextEventMatchingListInModeWithFilter (/System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.framework/Versions/A/HIToolbox+0x309ce)
    #59 0x7fff97bc6d95 in _DPSNextEvent (/System/Library/Frameworks/AppKit.framework/Versions/C/AppKit+0x49d95)
    #60 0x7fff97bc61c4 in -[NSApplication _nextEventMatchingEventMask:untilDate:inMode:dequeue:] (/System/Library/Frameworks/AppKit.framework/Versions/C/AppKit+0x491c4)
    #61 0x7fff97bbad27 in -[NSApplication run] (/System/Library/Frameworks/AppKit.framework/Versions/C/AppKit+0x3dd27)
    #62 0x7fff97b83fbd in NSApplicationMain (/System/Library/Frameworks/AppKit.framework/Versions/C/AppKit+0x6fbd)
    #63 0x7fff9408b4f1 in _xpc_objc_main (/usr/lib/system/libxpc.dylib+0x114f1)
    #64 0x7fff94089f1d in xpc_main (/usr/lib/system/libxpc.dylib+0xff1d)
    #65 0x10beb71cb in main (/Users/reni/work/WebKit/WebKitBuild/Debug/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.WebContent.Development.xpc/Contents/MacOS/com.apple.WebKit.WebContent.Development+0x1000021cb)
    #66 0x7fff908b05ac in start (/usr/lib/system/libdyld.dylib+0x35ac)
    #67 0x0  (&lt;unknown module&gt;)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV ??:0 WTFCrash
==82191==ABORTING
#CRASHED - com.apple.WebKit.WebContent.Development (pid 82191)
LEAK: 1 WebProcessPool
LEAK: 1 WebPageProxy</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1176511</commentid>
    <comment_count>1</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2016-03-19 13:47:59 -0700</bug_when>
    <thetext>This is pretty weird:

inline void RenderTableCell::setCol(unsigned column)
{
    if (UNLIKELY(column &gt; maxColumnIndex))
        CRASH();
    m_column = column;
}</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1176512</commentid>
    <comment_count>2</comment_count>
    <who name="alan">zalan</who>
    <bug_when>2016-03-19 13:49:42 -0700</bug_when>
    <thetext>(In reply to comment #1)
&gt; This is pretty weird:
&gt; 
&gt; inline void RenderTableCell::setCol(unsigned column)
&gt; {
&gt;     if (UNLIKELY(column &gt; maxColumnIndex))
&gt;         CRASH();
&gt;     m_column = column;
&gt; }
Indeed, it is.
I am going to find a better way to address the bitfield overflow issue.
see this for more info: bug 71135</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1176847</commentid>
    <comment_count>3</comment_count>
    <who name="alan">zalan</who>
    <bug_when>2016-03-21 14:47:13 -0700</bug_when>
    <thetext>rdar://problem/15895201</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1176863</commentid>
    <comment_count>4</comment_count>
      <attachid>274626</attachid>
    <who name="alan">zalan</who>
    <bug_when>2016-03-21 15:27:14 -0700</bug_when>
    <thetext>Created attachment 274626
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1176872</commentid>
    <comment_count>5</comment_count>
      <attachid>274626</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2016-03-21 16:30:00 -0700</bug_when>
    <thetext>Comment on attachment 274626
Patch

Clearing flags on attachment: 274626

Committed r198506: &lt;http://trac.webkit.org/changeset/198506&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1176873</commentid>
    <comment_count>6</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2016-03-21 16:30:05 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>274419</attachid>
            <date>2016-03-18 09:16:38 -0700</date>
            <delta_ts>2016-03-18 09:16:38 -0700</delta_ts>
            <desc>Test case</desc>
            <filename>test.html</filename>
            <type>text/html</type>
            <size>102</size>
            <attacher name="Renata Hodovan">rhodovan.u-szeged</attacher>
            
              <data encoding="base64">PCFET0NUWVBFIGh0bWw+Cjx0YWJsZT4KICAgIDx0ZCBjb2xzcGFuPSI1MzkyNzE0MiI+PC90ZD4K
ICAgIDx0aD4KICAgICAgICA8dGQ+PC90ZD4KICAgIDwvdGg+CjwvdGFibGU+
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>274626</attachid>
            <date>2016-03-21 15:27:14 -0700</date>
            <delta_ts>2016-03-21 16:30:00 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-155642-20160321152715.patch</filename>
            <type>text/plain</type>
            <size>3389</size>
            <attacher name="alan">zalan</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTk4Mzc0CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggZTI5MDIxMmZiOTNmYjI3
M2U5OTg2MGRjMzQ2YjVjYmNlNmU1NjMyMi4uNzEzY2YwMmNiY2RkYTQ3MDk1MjZkZGVmODNhMWNj
NDc5OGMxNWVmMiAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDE5IEBACisyMDE2LTAzLTIxICBaYWxh
biBCdWp0YXMgIDx6YWxhbkBhcHBsZS5jb20+CisKKyAgICAgICAgV2ViQ29yZTo6UmVuZGVyVGFi
bGVDZWxsOjpzZXRDb2wgc2hvdWxkIHB1dCBhIGNhcCBvbiB0aGUgY29sdW1uIHZhbHVlLiAKKyAg
ICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTE1NTY0MgorICAg
ICAgICA8cmRhcjovL3Byb2JsZW0vMTU4OTUyMDE+CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9C
T0RZIChPT1BTISkuCisKKyAgICAgICAgVGhpcyBwYXRjaCBlbnN1cmVzIHRoYXQgd2UgZG9uJ3Qg
Y3Jhc2ggd2hlbiB0aGUgY29sdW1uIG51bWJlciBpcyBsYXJnZSBlbm91Z2guCisgICAgICAgIHNl
ZSB3ZWJraXQub3JnL2IvNzExMzUgZm9yIG1vcmUgaW5mb3JtYXRpb24uCisKKyAgICAgICAgVGVz
dDogdGFibGVzL2NvbHNwYW4td2l0aC1sYXJnZS12YWx1ZS1jcmFzaC5odG1sCisKKyAgICAgICAg
KiByZW5kZXJpbmcvUmVuZGVyVGFibGVDZWxsLmg6CisgICAgICAgIChXZWJDb3JlOjpSZW5kZXJU
YWJsZUNlbGw6OnNldENvbCk6CisKIDIwMTYtMDMtMTcgIFphbGFuIEJ1anRhcyAgPHphbGFuQGFw
cGxlLmNvbT4KIAogICAgICAgICBJbWFnZXMgaW4gZmVlZCBvbiBlYmF5LmNvbSBqaWdnbGUgd2hl
biBvbmUgaXMgaG92ZXJlZApkaWZmIC0tZ2l0IGEvU291cmNlL1dlYkNvcmUvcmVuZGVyaW5nL1Jl
bmRlclRhYmxlQ2VsbC5oIGIvU291cmNlL1dlYkNvcmUvcmVuZGVyaW5nL1JlbmRlclRhYmxlQ2Vs
bC5oCmluZGV4IDhiNzZlMTY4YjUyNmRhYzFjZjMwOWM4YmYxNDBiNTk1MzFiZjg2YmMuLjgwNGY2
ZjBhMmYzNjgwOGY5YzFmMjc2NzIyOGQ1MTIyNjZlMDk4YTYgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9X
ZWJDb3JlL3JlbmRlcmluZy9SZW5kZXJUYWJsZUNlbGwuaAorKysgYi9Tb3VyY2UvV2ViQ29yZS9y
ZW5kZXJpbmcvUmVuZGVyVGFibGVDZWxsLmgKQEAgLTIzNyw3ICsyMzcsNyBAQCBpbmxpbmUgdW5z
aWduZWQgUmVuZGVyVGFibGVDZWxsOjpyb3dTcGFuKCkgY29uc3QKIGlubGluZSB2b2lkIFJlbmRl
clRhYmxlQ2VsbDo6c2V0Q29sKHVuc2lnbmVkIGNvbHVtbikKIHsKICAgICBpZiAoVU5MSUtFTFko
Y29sdW1uID4gbWF4Q29sdW1uSW5kZXgpKQotICAgICAgICBDUkFTSCgpOworICAgICAgICBjb2x1
bW4gPSBtYXhDb2x1bW5JbmRleDsKICAgICBtX2NvbHVtbiA9IGNvbHVtbjsKIH0KIApkaWZmIC0t
Z2l0IGEvTGF5b3V0VGVzdHMvQ2hhbmdlTG9nIGIvTGF5b3V0VGVzdHMvQ2hhbmdlTG9nCmluZGV4
IGMwYThmMjgwMTJmZmM0ZmQ2Mjc4MDVmOThiZDlkOTZiZDBmMTI3ZWQuLjNhYTJiMGExOTMzYWJm
MDc3ZWEzMTBjMWUyMzYyNDg2MzJjYWU1MzEgMTAwNjQ0Ci0tLSBhL0xheW91dFRlc3RzL0NoYW5n
ZUxvZworKysgYi9MYXlvdXRUZXN0cy9DaGFuZ2VMb2cKQEAgLTEsMyArMSwxNyBAQAorMjAxNi0w
My0yMSAgWmFsYW4gQnVqdGFzICA8emFsYW5AYXBwbGUuY29tPgorCisgICAgICAgIFdlYkNvcmU6
OlJlbmRlclRhYmxlQ2VsbDo6c2V0Q29sIHNob3VsZCBwdXQgYSBjYXAgb24gdGhlIGNvbHVtbiB2
YWx1ZS4gCisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0x
NTU2NDIKKyAgICAgICAgPHJkYXI6Ly9wcm9ibGVtLzE1ODk1MjAxPgorCisgICAgICAgIFJldmll
d2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIFRoaXMgcGF0Y2ggZW5zdXJlcyB0aGF0
IHdlIGRvbid0IGNyYXNoIHdoZW4gdGhlIGNvbHVtbiBudW1iZXIgaXMgbGFyZ2UgZW5vdWdoLgor
ICAgICAgICBzZWUgd2Via2l0Lm9yZy9iLzcxMTM1IGZvciBtb3JlIGluZm9ybWF0aW9uLgorCisg
ICAgICAgICogdGFibGVzL2NvbHNwYW4td2l0aC1sYXJnZS12YWx1ZS1jcmFzaC1leHBlY3RlZC50
eHQ6IEFkZGVkLgorICAgICAgICAqIHRhYmxlcy9jb2xzcGFuLXdpdGgtbGFyZ2UtdmFsdWUtY3Jh
c2guaHRtbDogQWRkZWQuCisKIDIwMTYtMDMtMTcgIFphbGFuIEJ1anRhcyAgPHphbGFuQGFwcGxl
LmNvbT4KIAogICAgICAgICBJbWFnZXMgaW4gZmVlZCBvbiBlYmF5LmNvbSBqaWdnbGUgd2hlbiBv
bmUgaXMgaG92ZXJlZApkaWZmIC0tZ2l0IGEvTGF5b3V0VGVzdHMvdGFibGVzL2NvbHNwYW4td2l0
aC1sYXJnZS12YWx1ZS1jcmFzaC1leHBlY3RlZC50eHQgYi9MYXlvdXRUZXN0cy90YWJsZXMvY29s
c3Bhbi13aXRoLWxhcmdlLXZhbHVlLWNyYXNoLWV4cGVjdGVkLnR4dApuZXcgZmlsZSBtb2RlIDEw
MDY0NAppbmRleCAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwLi43MzQw
OWFlYThkZmFkMzkzZTdlMjc1Njc3MzNkMjk1ODdlODAxMjE4Ci0tLSAvZGV2L251bGwKKysrIGIv
TGF5b3V0VGVzdHMvdGFibGVzL2NvbHNwYW4td2l0aC1sYXJnZS12YWx1ZS1jcmFzaC1leHBlY3Rl
ZC50eHQKQEAgLTAsMCArMSwyIEBACitQQVNTIGlmIG5vIGNyYXNoLgorCmRpZmYgLS1naXQgYS9M
YXlvdXRUZXN0cy90YWJsZXMvY29sc3Bhbi13aXRoLWxhcmdlLXZhbHVlLWNyYXNoLmh0bWwgYi9M
YXlvdXRUZXN0cy90YWJsZXMvY29sc3Bhbi13aXRoLWxhcmdlLXZhbHVlLWNyYXNoLmh0bWwKbmV3
IGZpbGUgbW9kZSAxMDA2NDQKaW5kZXggMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw
MDAwMDAwMC4uOTNmMzEyYTYwZjUwZGU0NThhZTMyZTRlZDZkOTVkMzFhNGZmOTAzOAotLS0gL2Rl
di9udWxsCisrKyBiL0xheW91dFRlc3RzL3RhYmxlcy9jb2xzcGFuLXdpdGgtbGFyZ2UtdmFsdWUt
Y3Jhc2guaHRtbApAQCAtMCwwICsxLDE5IEBACis8IURPQ1RZUEUgaHRtbD4KKzxodG1sPgorPGhl
YWQ+Cis8dGl0bGU+VGhpcyB0ZXN0cyB0aGF0IHdlIGRvIG5vdCBjcmFzaCB3aGVuIGNvbHNwYW4g
dmFsdWUgaXMgbGFyZ2UuPC90aXRsZT4KKzwvaGVhZD4KKzxib2R5PgorUEFTUyBpZiBubyBjcmFz
aC4KKzx0YWJsZT4KKyAgICA8dGQgY29sc3Bhbj0iNTM5MjcxNDIiPjwvdGQ+CisgICAgPHRoPgor
ICAgICAgICA8dGQ+PC90ZD4KKyAgICA8L3RoPgorPC90YWJsZT4KKzxzY3JpcHQ+CisgICAgaWYg
KHdpbmRvdy50ZXN0UnVubmVyKQorICAgICAgICB0ZXN0UnVubmVyLmR1bXBBc1RleHQoKTsKKzwv
c2NyaXB0PgorPC9ib2R5PgorPC9odG1sPgo=
</data>

          </attachment>
      

    </bug>

</bugzilla>