<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>18722</bug_id>
          
          <creation_ts>2008-04-24 15:58:10 -0700</creation_ts>
          <short_desc>Webkit Nightly Build crashes when visiting i has a hotdog.</short_desc>
          <delta_ts>2008-05-29 15:02:44 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Layout and Rendering</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://ihasahotdog.com</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar, NeedsReduction, Regression</keywords>
          <priority>P1</priority>
          <bug_severity>Major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Mattias Stahre">mattias</reporter>
          <assigned_to>mitz</assigned_to>
          <cc>dave</cc>
    
    <cc>mitz</cc>
    
    <cc>mrowe</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>78828</commentid>
    <comment_count>0</comment_count>
    <who name="Mattias Stahre">mattias</who>
    <bug_when>2008-04-24 15:58:10 -0700</bug_when>
    <thetext>When visiting ihasahotdog.com there is an instant crash of the webbrowser when using nightly builds, however, the &quot;stable&quot; Safari 3.1 do not crash when visiting this site.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78831</commentid>
    <comment_count>1</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-04-24 16:03:05 -0700</bug_when>
    <thetext>Exception Type:  EXC_BAD_ACCESS (SIGBUS)
Exception Codes: KERN_PROTECTION_FAILURE at 0x00000000000001d4
Crashed Thread:  0

Thread 0 Crashed:
0   com.apple.WebCore             	0x0107bf6b WebCore::RenderBlock::determineStartPosition(bool&amp;, WebCore::BidiResolver&lt;WebCore::BidiIterator, WebCore::BidiRun&gt;&amp;, WTF::Vector&lt;WebCore::RenderBlock::FloatWithRect, 0ul&gt;&amp;, unsigned int&amp;) + 283
1   com.apple.WebCore             	0x0107f7af WebCore::RenderBlock::layoutInlineChildren(bool, int&amp;, int&amp;) + 1039
2   com.apple.WebCore             	0x00eb3e8c WebCore::RenderBlock::layoutBlock(bool) + 716
3   com.apple.WebCore             	0x00ea5f28 WebCore::RenderBlock::layout() + 40
4   com.apple.WebCore             	0x00eb023f WebCore::RenderBlock::layoutBlockChildren(bool, int&amp;) + 1935
5   com.apple.WebCore             	0x00eb43b9 WebCore::RenderBlock::layoutBlock(bool) + 2041
6   com.apple.WebCore             	0x00ea5f28 WebCore::RenderBlock::layout() + 40
7   com.apple.WebCore             	0x00eb023f WebCore::RenderBlock::layoutBlockChildren(bool, int&amp;) + 1935
8   com.apple.WebCore             	0x00eb43b9 WebCore::RenderBlock::layoutBlock(bool) + 2041
9   com.apple.WebCore             	0x00ea5f28 WebCore::RenderBlock::layout() + 40
10  com.apple.WebCore             	0x00eb023f WebCore::RenderBlock::layoutBlockChildren(bool, int&amp;) + 1935
11  com.apple.WebCore             	0x00eb43b9 WebCore::RenderBlock::layoutBlock(bool) + 2041
12  com.apple.WebCore             	0x00ea5f28 WebCore::RenderBlock::layout() + 40
13  com.apple.WebCore             	0x00ea7ca4 WebCore::RenderBlock::insertFloatingObject(WebCore::RenderObject*) + 116
14  com.apple.WebCore             	0x00eaf637 WebCore::RenderBlock::handleFloatingChild(WebCore::RenderObject*, WebCore::RenderBlock::MarginInfo const&amp;, bool&amp;) + 39
15  com.apple.WebCore             	0x00eaf6ca WebCore::RenderBlock::handleSpecialChild(WebCore::RenderObject*, WebCore::RenderBlock::MarginInfo const&amp;, WebCore::RenderBlock::CompactInfo&amp;, bool&amp;) + 106
16  com.apple.WebCore             	0x00eafc11 WebCore::RenderBlock::layoutBlockChildren(bool, int&amp;) + 353
17  com.apple.WebCore             	0x00eb43b9 WebCore::RenderBlock::layoutBlock(bool) + 2041

</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78832</commentid>
    <comment_count>2</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-04-24 16:03:45 -0700</bug_when>
    <thetext>&lt;rdar://problem/5888360&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78833</commentid>
    <comment_count>3</comment_count>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-04-24 16:04:12 -0700</bug_when>
    <thetext>Crash log was from r32516.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78857</commentid>
    <comment_count>4</comment_count>
      <attachid>20806</attachid>
    <who name="">mitz</who>
    <bug_when>2008-04-24 20:55:21 -0700</bug_when>
    <thetext>Created attachment 20806
Patch with regression test</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78858</commentid>
    <comment_count>5</comment_count>
      <attachid>20806</attachid>
    <who name="Dave Hyatt">hyatt</who>
    <bug_when>2008-04-24 21:03:07 -0700</bug_when>
    <thetext>Comment on attachment 20806
Patch with regression test

r=me, but I&apos;m taking off points for you not saying &quot;I can haz review?&quot; when you posted the patch.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78859</commentid>
    <comment_count>6</comment_count>
    <who name="">mitz</who>
    <bug_when>2008-04-24 21:08:22 -0700</bug_when>
    <thetext>Fixed in &lt;http://trac.webkit.org/projects/webkit/changeset/32532&gt;.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>81894</commentid>
    <comment_count>7</comment_count>
    <who name="">mitz</who>
    <bug_when>2008-05-29 15:02:44 -0700</bug_when>
    <thetext>*** Bug 18639 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>20806</attachid>
            <date>2008-04-24 20:55:21 -0700</date>
            <delta_ts>2008-04-24 21:03:07 -0700</delta_ts>
            <desc>Patch with regression test</desc>
            <filename>18722_r1.diff</filename>
            <type>text/plain</type>
            <size>5234</size>
            <attacher>mitz</attacher>
            
              <data encoding="base64">SW5kZXg6IFdlYkNvcmUvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFdlYkNvcmUvQ2hhbmdlTG9n
CShyZXZpc2lvbiAzMjUzMSkKKysrIFdlYkNvcmUvQ2hhbmdlTG9nCSh3b3JraW5nIGNvcHkpCkBA
IC0xLDMgKzEsMTggQEAKKzIwMDgtMDQtMjQgIERhbiBCZXJuc3RlaW4gIDxtaXR6QGFwcGxlLmNv
bT4KKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICAtIGZp
eCBodHRwczovL2J1Z3Mud2Via2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9MTg3MjIKKyAgICAgICAg
ICA8cmRhcjovL3Byb2JsZW0vNTg4ODM2MD4gUkVHUkVTU0lPTiAoMy4xIC0+IFRPVCk6IFdlYmtp
dCBOaWdodGx5IEJ1aWxkIGNyYXNoZXMgd2hlbiB2aXNpdGluZyBpIGhhcyBhIGhvdGRvZworCisg
ICAgICAgIFRlc3Q6IGZhc3QvZHluYW1pYy9mbG9hdC1yZW1vdmUtYWJvdmUtbGluZS5odG1sCisK
KyAgICAgICAgKiByZW5kZXJpbmcvYmlkaS5jcHA6CisgICAgICAgIChXZWJDb3JlOjpSZW5kZXJC
bG9jazo6bGF5b3V0SW5saW5lQ2hpbGRyZW4pOiBBdm9pZCBhZGRpbmcgZmxvYXRzIHRoYXQKKyAg
ICAgICAgZG8gbm90IGludHJ1ZGUgaW50byB0aGUgbGluZSB0byBpdHMgZmxvYXRzIHZlY3Rvci4g
V2hlbiBzdWNoIGZsb2F0cyBnbworICAgICAgICBhd2F5LCB0aGV5IGRvIG5vdCBkaXJ0eSB0aGUg
bGluZSAoYmVjYXVzZSB0aGV5IGRvIG5vdCBpbnRlcnNlY3Qgd2l0aCBpdCkKKyAgICAgICAgYW5k
IGhhdmluZyBpdCBrZWVwIHRoZW0gaW4gaXRzIGZsb2F0cyB2ZWN0b3IgaXMgd2hhdCBjYXVzZWQg
dGhlIGNyYXNoLgorCiAyMDA4LTA0LTI0ICBKdXN0aW4gR2FyY2lhICA8anVzdGluLmdhcmNpYUBh
cHBsZS5jb20+CiAKICAgICAgICAgUmV2aWV3ZWQgYnkgSm9obiBTdWxsaXZhbi4KSW5kZXg6IFdl
YkNvcmUvcmVuZGVyaW5nL2JpZGkuY3BwCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFdlYkNvcmUvcmVuZGVyaW5n
L2JpZGkuY3BwCShyZXZpc2lvbiAzMjUzMSkKKysrIFdlYkNvcmUvcmVuZGVyaW5nL2JpZGkuY3Bw
CSh3b3JraW5nIGNvcHkpCkBAIC05MjgsNiArOTI4LDcgQEAgdm9pZCBSZW5kZXJCbG9jazo6bGF5
b3V0SW5saW5lQ2hpbGRyZW4oYgogCiAgICAgICAgIGJvb2wgZW5kTGluZU1hdGNoZWQgPSBmYWxz
ZTsKICAgICAgICAgYm9vbCBjaGVja0ZvckVuZExpbmVNYXRjaCA9IGVuZExpbmU7CisgICAgICAg
IGludCBsYXN0SGVpZ2h0ID0gbV9oZWlnaHQ7CiAKICAgICAgICAgd2hpbGUgKCFlbmQuYXRFbmQo
KSkgewogICAgICAgICAgICAgLy8gRklYTUU6IElzIHRoaXMgY2hlY2sgbmVjZXNzYXJ5IGJlZm9y
ZSB0aGUgZmlyc3QgaXRlcmF0aW9uIG9yIGNhbiBpdCBiZSBtb3ZlZCB0byB0aGUgZW5kPwpAQCAt
MTA1OCw3ICsxMDU5LDggQEAgdm9pZCBSZW5kZXJCbG9jazo6bGF5b3V0SW5saW5lQ2hpbGRyZW4o
YgogICAgICAgICAgICAgICAgIH0gZWxzZQogICAgICAgICAgICAgICAgICAgICBtX2Zsb2F0aW5n
T2JqZWN0cy0+Zmlyc3QoKTsKICAgICAgICAgICAgICAgICBmb3IgKEZsb2F0aW5nT2JqZWN0KiBm
ID0gbV9mbG9hdGluZ09iamVjdHMtPmN1cnJlbnQoKTsgZjsgZiA9IG1fZmxvYXRpbmdPYmplY3Rz
LT5uZXh0KCkpIHsKLSAgICAgICAgICAgICAgICAgICAgbGFzdFJvb3RCb3goKS0+ZmxvYXRzKCku
YXBwZW5kKGYtPm1fcmVuZGVyZXIpOworICAgICAgICAgICAgICAgICAgICBpZiAoZi0+bV9ib3R0
b20gPiBsYXN0SGVpZ2h0KQorICAgICAgICAgICAgICAgICAgICAgICAgbGFzdFJvb3RCb3goKS0+
ZmxvYXRzKCkuYXBwZW5kKGYtPm1fcmVuZGVyZXIpOwogICAgICAgICAgICAgICAgICAgICBBU1NF
UlQoZi0+bV9yZW5kZXJlciA9PSBmbG9hdHNbZmxvYXRJbmRleF0ub2JqZWN0KTsKICAgICAgICAg
ICAgICAgICAgICAgLy8gSWYgYSBmbG9hdCdzIGdlb21ldHJ5IGhhcyBjaGFuZ2VkLCBnaXZlIHVw
IG9uIHN5bmNpbmcgd2l0aCBjbGVhbiBsaW5lcy4KICAgICAgICAgICAgICAgICAgICAgaWYgKGZs
b2F0c1tmbG9hdEluZGV4XS5yZWN0ICE9IEludFJlY3QoZi0+bV9sZWZ0LCBmLT5tX3RvcCwgZi0+
bV93aWR0aCwgZi0+bV9ib3R0b20gLSBmLT5tX3RvcCkpCkBAIC0xMDY4LDYgKzEwNzAsNyBAQCB2
b2lkIFJlbmRlckJsb2NrOjpsYXlvdXRJbmxpbmVDaGlsZHJlbihiCiAgICAgICAgICAgICAgICAg
bGFzdEZsb2F0ID0gbV9mbG9hdGluZ09iamVjdHMtPmxhc3QoKTsKICAgICAgICAgICAgIH0KIAor
ICAgICAgICAgICAgbGFzdEhlaWdodCA9IG1faGVpZ2h0OwogICAgICAgICAgICAgc051bU1pZHBv
aW50cyA9IDA7CiAgICAgICAgICAgICBzQ3Vyck1pZHBvaW50ID0gMDsKICAgICAgICAgICAgIHN0
YXJ0LnNldFBvc2l0aW9uKGVuZCk7CkBAIC0xMTE5LDggKzExMjIsMTAgQEAgdm9pZCBSZW5kZXJC
bG9jazo6bGF5b3V0SW5saW5lQ2hpbGRyZW4oYgogICAgICAgICAgICAgICAgICAgICBtX2Zsb2F0
aW5nT2JqZWN0cy0+bmV4dCgpOwogICAgICAgICAgICAgICAgIH0gZWxzZQogICAgICAgICAgICAg
ICAgICAgICBtX2Zsb2F0aW5nT2JqZWN0cy0+Zmlyc3QoKTsKLSAgICAgICAgICAgICAgICBmb3Ig
KEZsb2F0aW5nT2JqZWN0KiBmID0gbV9mbG9hdGluZ09iamVjdHMtPmN1cnJlbnQoKTsgZjsgZiA9
IG1fZmxvYXRpbmdPYmplY3RzLT5uZXh0KCkpCi0gICAgICAgICAgICAgICAgICAgIGxhc3RSb290
Qm94KCktPmZsb2F0cygpLmFwcGVuZChmLT5tX3JlbmRlcmVyKTsKKyAgICAgICAgICAgICAgICBm
b3IgKEZsb2F0aW5nT2JqZWN0KiBmID0gbV9mbG9hdGluZ09iamVjdHMtPmN1cnJlbnQoKTsgZjsg
ZiA9IG1fZmxvYXRpbmdPYmplY3RzLT5uZXh0KCkpIHsKKyAgICAgICAgICAgICAgICAgICAgaWYg
KGYtPm1fYm90dG9tID4gbGFzdEhlaWdodCkKKyAgICAgICAgICAgICAgICAgICAgICAgIGxhc3RS
b290Qm94KCktPmZsb2F0cygpLmFwcGVuZChmLT5tX3JlbmRlcmVyKTsKKyAgICAgICAgICAgICAg
ICB9CiAgICAgICAgICAgICAgICAgbGFzdEZsb2F0ID0gbV9mbG9hdGluZ09iamVjdHMtPmxhc3Qo
KTsKICAgICAgICAgICAgIH0KICAgICAgICAgfQpJbmRleDogTGF5b3V0VGVzdHMvQ2hhbmdlTG9n
Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT0KLS0tIExheW91dFRlc3RzL0NoYW5nZUxvZwkocmV2aXNpb24gMzI1MzEpCisr
KyBMYXlvdXRUZXN0cy9DaGFuZ2VMb2cJKHdvcmtpbmcgY29weSkKQEAgLTEsMyArMSwxMyBAQAor
MjAwOC0wNC0yNCAgRGFuIEJlcm5zdGVpbiAgPG1pdHpAYXBwbGUuY29tPgorCisgICAgICAgIFJl
dmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIC0gdGVzdCBmb3IgaHR0cHM6Ly9i
dWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTE4NzIyCisgICAgICAgICAgPHJkYXI6Ly9w
cm9ibGVtLzU4ODgzNjA+IFJFR1JFU1NJT04gKDMuMSAtPiBUT1QpOiBXZWJraXQgTmlnaHRseSBC
dWlsZCBjcmFzaGVzIHdoZW4gdmlzaXRpbmcgaSBoYXMgYSBob3Rkb2cKKworICAgICAgICAqIGZh
c3QvZHluYW1pYy9mbG9hdC1yZW1vdmUtYWJvdmUtbGluZS1leHBlY3RlZC50eHQ6IEFkZGVkLgor
ICAgICAgICAqIGZhc3QvZHluYW1pYy9mbG9hdC1yZW1vdmUtYWJvdmUtbGluZS5odG1sOiBBZGRl
ZC4KKwogMjAwOC0wNC0yNCAgQ2FtZXJvbiBNY0Nvcm1hY2sgIDxjYW1AbWNjLmlkLmF1PgogCiAg
ICAgICAgIFJldmlld2VkIGJ5IE1hY2llaiBTdGFjaG93aWFrLgpJbmRleDogTGF5b3V0VGVzdHMv
ZmFzdC9keW5hbWljL2Zsb2F0LXJlbW92ZS1hYm92ZS1saW5lLWV4cGVjdGVkLnR4dAo9PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09Ci0tLSBMYXlvdXRUZXN0cy9mYXN0L2R5bmFtaWMvZmxvYXQtcmVtb3ZlLWFib3ZlLWxpbmUt
ZXhwZWN0ZWQudHh0CShyZXZpc2lvbiAwKQorKysgTGF5b3V0VGVzdHMvZmFzdC9keW5hbWljL2Zs
b2F0LXJlbW92ZS1hYm92ZS1saW5lLWV4cGVjdGVkLnR4dAkocmV2aXNpb24gMCkKQEAgLTAsMCAr
MSw3IEBACitUZXN0IGZvciBodHRwczovL2J1Z3Mud2Via2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9
MTg3MjIgV2Via2l0IE5pZ2h0bHkgQnVpbGQgY3Jhc2hlcyB3aGVuIHZpc2l0aW5nIGkgaGFzIGEg
aG90ZG9nLgorCitUaGUgdGVzdCBwYXNzZXMgaWYgaXQgZG9lcyBub3QgY3Jhc2guCisKK2Zvbwor
YmFyCisKSW5kZXg6IExheW91dFRlc3RzL2Zhc3QvZHluYW1pYy9mbG9hdC1yZW1vdmUtYWJvdmUt
bGluZS5odG1sCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT0KLS0tIExheW91dFRlc3RzL2Zhc3QvZHluYW1pYy9mbG9hdC1y
ZW1vdmUtYWJvdmUtbGluZS5odG1sCShyZXZpc2lvbiAwKQorKysgTGF5b3V0VGVzdHMvZmFzdC9k
eW5hbWljL2Zsb2F0LXJlbW92ZS1hYm92ZS1saW5lLmh0bWwJKHJldmlzaW9uIDApCkBAIC0wLDAg
KzEsMTggQEAKKzxwPgorICAgIFRlc3QgZm9yIDxpPjxhIGhyZWY9Imh0dHBzOi8vYnVncy53ZWJr
aXQub3JnL3Nob3dfYnVnLmNnaT9pZD0xODcyMiI+aHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hv
d19idWcuY2dpP2lkPTE4NzIyPC9hPgorICAgIFdlYmtpdCBOaWdodGx5IEJ1aWxkIGNyYXNoZXMg
d2hlbiB2aXNpdGluZyBpIGhhcyBhIGhvdGRvZzwvaT4uCis8L3A+Cis8cD4KKyAgICBUaGUgdGVz
dCBwYXNzZXMgaWYgaXQgZG9lcyBub3QgY3Jhc2guCis8L3A+Cis8ZGl2PgorICAgIGZvbzxicj5i
YXIKKyAgICA8ZGl2IGlkPSJmbG9hdCIgc3R5bGU9ImZsb2F0OiByaWdodDsgaGVpZ2h0OiAxMHB4
OyB3aWR0aDogMTBweDsgYmFja2dyb3VuZC1jb2xvcjogbGlnaHRibHVlOyBtYXJnaW4tdG9wOiAt
MTBweDsiPjwvZGl2PgorPGRpdj4KKzxzY3JpcHQ+CisgICAgaWYgKHdpbmRvdy5sYXlvdXRUZXN0
Q29udHJvbGxlcikKKyAgICAgICAgbGF5b3V0VGVzdENvbnRyb2xsZXIuZHVtcEFzVGV4dCgpOwor
CisgICAgZG9jdW1lbnQuYm9keS5vZmZzZXRUb3A7CisgICAgZG9jdW1lbnQuZ2V0RWxlbWVudEJ5
SWQoImZsb2F0Iikuc3R5bGUuZGlzcGxheSA9ICJub25lIjsKKzwvc2NyaXB0Pgo=
</data>
<flag name="review"
          id="9096"
          type_id="1"
          status="+"
          setter="hyatt"
    />
          </attachment>
      

    </bug>

</bugzilla>