<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>196035</bug_id>
          
          <creation_ts>2019-03-20 14:58:26 -0700</creation_ts>
          <short_desc>[iOS] Crash in WebCore::Node::renderRect</short_desc>
          <delta_ts>2019-03-20 15:49:59 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>UI Events</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Dean Jackson">dino</reporter>
          <assigned_to name="Dean Jackson">dino</assigned_to>
          <cc>cdumez</cc>
    
    <cc>dbates</cc>
    
    <cc>esprehn+autocc</cc>
    
    <cc>ews-watchlist</cc>
    
    <cc>graouts</cc>
    
    <cc>kangil.han</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1519213</commentid>
    <comment_count>0</comment_count>
    <who name="Dean Jackson">dino</who>
    <bug_when>2019-03-20 14:58:26 -0700</bug_when>
    <thetext>Since https://trac.webkit.org/changeset/242757/webkit

fast/images/imagemap-in-shadow-tree.html
http/tests/download/area-download.html


ASSERTION FAILED: hitRenderer
./dom/Node.cpp(798) : WebCore::LayoutRect WebCore::Node::renderRect(bool *)
1   0x2c641f649 WTFCrash
2   0x2ca4eda7b WTFCrashWithInfo(int, char const*, char const*, int)
3   0x2cc6f207e WebCore::Node::renderRect(bool*)
4   0x105ac91b9 WebKit::ViewGestureGeometryCollector::computeZoomInformationForNode(WebCore::Node&amp;, WebCore::FloatPoint&amp;, WebCore::FloatRect&amp;, bool&amp;, double&amp;, double&amp;)
5   0x1057acf6b WebKit::WebPage::potentialTapAtPosition(unsigned long long, WebCore::FloatPoint const&amp;, bool)
6   0x105c10e37 void IPC::callMemberFunctionImpl&lt;WebKit::WebPage, void (WebKit::WebPage::*)(unsigned long long, WebCore::FloatPoint const&amp;, bool), std::__1::tuple&lt;unsigned long long, WebCore::FloatPoint, bool&gt;, 0ul, 1ul, 2ul&gt;(WebKit::WebPage*, void (WebKit::WebPage::*)(unsigned long long, WebCore::FloatPoint const&amp;, bool), std::__1::tuple&lt;unsigned long long, WebCore::FloatPoint, bool&gt;&amp;&amp;, std::__1::integer_sequence&lt;unsigned long, 0ul, 1ul, 2ul&gt;)
7   0x105c10d10 void IPC::callMemberFunction&lt;WebKit::WebPage, void (WebKit::WebPage::*)(unsigned long long, WebCore::FloatPoint const&amp;, bool), std::__1::tuple&lt;unsigned long long, WebCore::FloatPoint, bool&gt;, std::__1::integer_sequence&lt;unsigned long, 0ul, 1ul, 2ul&gt; &gt;(std::__1::tuple&lt;unsigned long long, WebCore::FloatPoint, bool&gt;&amp;&amp;, WebKit::WebPage*, void (WebKit::WebPage::*)(unsigned long long, WebCore::FloatPoint const&amp;, bool))
8   0x105bf26d6 void IPC::handleMessage&lt;Messages::WebPage::PotentialTapAtPosition, WebKit::WebPage, void (WebKit::WebPage::*)(unsigned long long, WebCore::FloatPoint const&amp;, bool)&gt;(IPC::Decoder&amp;, WebKit::WebPage*, void (WebKit::WebPage::*)(unsigned long long, WebCore::FloatPoint const&amp;, bool))
9   0x105be8512 WebKit::WebPage::didReceiveWebPageMessage(IPC::Connection&amp;, IPC::Decoder&amp;)
10  0x105b918ae WebKit::WebPage::didReceiveMessage(IPC::Connection&amp;, IPC::Decoder&amp;)
11  0x104b1cf6a IPC::MessageReceiverMap::dispatchMessage(IPC::Connection&amp;, IPC::Decoder&amp;)
12  0x1057f3afd WebKit::WebProcess::didReceiveMessage(IPC::Connection&amp;, IPC::Decoder&amp;)
13  0x104ad029c IPC::Connection::dispatchMessage(IPC::Decoder&amp;)
14  0x104ac2881 IPC::Connection::dispatchMessage(std::__1::unique_ptr&lt;IPC::Decoder, std::__1::default_delete&lt;IPC::Decoder&gt; &gt;)
15  0x104ad1067 IPC::Connection::dispatchOneIncomingMessage()
16  0x104af1cf8 IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::Decoder, std::__1::default_delete&lt;IPC::Decoder&gt; &gt;)::$_14::operator()()
17  0x104af1c09 WTF::Function&lt;void ()&gt;::CallableWrapper&lt;IPC::Connection::enqueueIncomingMessage(std::__1::unique_ptr&lt;IPC::Decoder, std::__1::default_delete&lt;IPC::Decoder&gt; &gt;)::$_14&gt;::call()
18  0x2c6449add WTF::Function&lt;void ()&gt;::operator()() const
19  0x2c64a9233 WTF::RunLoop::performWork()
20  0x2c64a9bc4 WTF::RunLoop::performWork(void*)
21  0x2c0b9a721 __CFRUNLOOP_IS_CALLING_OUT_TO_A_SOURCE0_PERFORM_FUNCTION__
22  0x2c0b99f93 __CFRunLoopDoSources0
23  0x2c0b9463f __CFRunLoopRun
24  0x2c0b93e11 CFRunLoopRunSpecific
25  0x104508322 -[NSRunLoop(NSRunLoop) runMode:beforeDate:]
26  0x104508492 -[NSRunLoop(NSRunLoop) run]
27  0x2c22f7812 _xpc_objc_main
28  0x2c22f9cbd xpc_main
29  0x104f6d427 WebKit::XPCServiceMain(int, char const**)
30  0x104e83a6b WKXPCServiceMain
31  0x10444da8e main
LEAK: 1 WebPageProxy
￼</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1519216</commentid>
    <comment_count>1</comment_count>
    <who name="Dean Jackson">dino</who>
    <bug_when>2019-03-20 14:59:05 -0700</bug_when>
    <thetext>&lt;rdar://problem/49076783&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1519247</commentid>
    <comment_count>2</comment_count>
      <attachid>365416</attachid>
    <who name="Dean Jackson">dino</who>
    <bug_when>2019-03-20 15:42:11 -0700</bug_when>
    <thetext>Created attachment 365416
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1519252</commentid>
    <comment_count>3</comment_count>
      <attachid>365416</attachid>
    <who name="Antoine Quint">graouts</who>
    <bug_when>2019-03-20 15:47:34 -0700</bug_when>
    <thetext>Comment on attachment 365416
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=365416&amp;action=review

&gt; Source/WebCore/dom/Node.cpp:799
&gt; +    if (!hitRenderer &amp;&amp; is&lt;HTMLAreaElement&gt;(*this)) {

You can use simply `this` here.

&gt; Source/WebCore/dom/Node.cpp:802
&gt; +        auto* imageElement = area.imageElement();
&gt; +        if (imageElement)

if (auto* …)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1519255</commentid>
    <comment_count>4</comment_count>
    <who name="Dean Jackson">dino</who>
    <bug_when>2019-03-20 15:49:59 -0700</bug_when>
    <thetext>Committed r243249: &lt;https://trac.webkit.org/changeset/243249&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>365416</attachid>
            <date>2019-03-20 15:42:11 -0700</date>
            <delta_ts>2019-03-20 15:47:34 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-196035-20190321094210.patch</filename>
            <type>text/plain</type>
            <size>2363</size>
            <attacher name="Dean Jackson">dino</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMjQzMTgzCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggMWE2MmUyZGM3MzdiOTgx
YmRhNTIwZDk5MGIwZTUyYTMzNjkzMTFlYS4uOWI4OTQ2ZjdhZWY5MjFmZWQ2NzI3OWRkM2JkMzNm
ZGQyZjIwYTU4ZiAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDI2IEBACisyMDE5LTAzLTIwICBEZWFu
IEphY2tzb24gIDxkaW5vQGFwcGxlLmNvbT4KKworICAgICAgICBbaU9TXSBDcmFzaCBpbiBXZWJD
b3JlOjpOb2RlOjpyZW5kZXJSZWN0CisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3No
b3dfYnVnLmNnaT9pZD0xOTYwMzUKKyAgICAgICAgPHJkYXI6Ly9wcm9ibGVtLzQ5MDc2NzgzPgor
CisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIFdoZW4gcmVu
ZGVyUmVjdCB3YXMgY2FsbGVkIG9uIGFuIEhUTUxBcmVhRWxlbWVudCwgaXQgd291bGQKKyAgICAg
ICAgQVNTRVJUIGJlY2F1c2UgaXQgZG9lc24ndCBoYXZlIGEgcmVuZGVyZXIuIFdlIGhhZG4ndCBu
b3RpY2VkCisgICAgICAgIHRoaXMgYmVmb3JlIGJlY2F1c2Ugbm9uZSBvZiBvdXIgdGVzdHMgd2Vy
ZSBoaXR0aW5nIHRoaXMgaW4KKyAgICAgICAgZGVidWcgbW9kZS4KKworICAgICAgICBUaGUgZml4
IGlzIHRvIGFzayB0aGUgY29ycmVzcG9uZGluZyBIVE1MSW1hZ2VFbGVtZW50IGZvcgorICAgICAg
ICBpdHMgcmVuZGVyZXIsIGFuZCB1c2UgdGhhdCBmb3IgdGhlIHJldHVybmVkIHJlY3RhbmdsZS4K
KworICAgICAgICBDb3ZlcmVkIGJ5IHRoZXNlIHRlc3RzIHRoYXQgaGFkIGJlY29tZSBmbGFrZXk6
CisgICAgICAgICAgICBmYXN0L2ltYWdlcy9pbWFnZW1hcC1pbi1zaGFkb3ctdHJlZS5odG1sCisg
ICAgICAgICAgICBodHRwL3Rlc3RzL2Rvd25sb2FkL2FyZWEtZG93bmxvYWQuaHRtbAorCisgICAg
ICAgICogZG9tL05vZGUuY3BwOgorICAgICAgICAoV2ViQ29yZTo6Tm9kZTo6cmVuZGVyUmVjdCk6
CisKIDIwMTktMDMtMTkgIFNhaWQgQWJvdS1IYWxsYXdhICA8c2Fib3VoYWxsYXdhQGFwcGxlLmNv
bT4KIAogICAgICAgICBSZW1vdmUgdGhlIFNWRyBwcm9wZXJ0eSB0ZWFyIG9mZiBvYmplY3RzIG9m
IFNWR0FuaW1hdGVkUmVjdApkaWZmIC0tZ2l0IGEvU291cmNlL1dlYkNvcmUvZG9tL05vZGUuY3Bw
IGIvU291cmNlL1dlYkNvcmUvZG9tL05vZGUuY3BwCmluZGV4IGU5ZmYxYjMyYzdlZjMwNjQ0NjI5
Y2IyZDNmNmY5ODI3YmMyZmVlYjYuLjRjMjQ2ZTA2ZjU3Njg2YjdkMjViMWE4ZGM1NjQ3ZWJmZmE5
ODYwOTkgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJDb3JlL2RvbS9Ob2RlLmNwcAorKysgYi9Tb3Vy
Y2UvV2ViQ29yZS9kb20vTm9kZS5jcHAKQEAgLTQyLDYgKzQyLDcgQEAKICNpbmNsdWRlICJFdmVu
dERpc3BhdGNoZXIuaCIKICNpbmNsdWRlICJFdmVudEhhbmRsZXIuaCIKICNpbmNsdWRlICJGcmFt
ZVZpZXcuaCIKKyNpbmNsdWRlICJIVE1MQXJlYUVsZW1lbnQuaCIKICNpbmNsdWRlICJIVE1MQm9k
eUVsZW1lbnQuaCIKICNpbmNsdWRlICJIVE1MQ29sbGVjdGlvbi5oIgogI2luY2x1ZGUgIkhUTUxF
bGVtZW50LmgiCkBAIC03OTUsNyArNzk2LDEyIEBAIFJlbmRlckJveE1vZGVsT2JqZWN0KiBOb2Rl
OjpyZW5kZXJCb3hNb2RlbE9iamVjdCgpIGNvbnN0CiBMYXlvdXRSZWN0IE5vZGU6OnJlbmRlclJl
Y3QoYm9vbCogaXNSZXBsYWNlZCkKIHsgICAgCiAgICAgUmVuZGVyT2JqZWN0KiBoaXRSZW5kZXJl
ciA9IHRoaXMtPnJlbmRlcmVyKCk7Ci0gICAgQVNTRVJUKGhpdFJlbmRlcmVyKTsKKyAgICBpZiAo
IWhpdFJlbmRlcmVyICYmIGlzPEhUTUxBcmVhRWxlbWVudD4oKnRoaXMpKSB7CisgICAgICAgIGF1
dG8mIGFyZWEgPSBkb3duY2FzdDxIVE1MQXJlYUVsZW1lbnQ+KCp0aGlzKTsKKyAgICAgICAgYXV0
byogaW1hZ2VFbGVtZW50ID0gYXJlYS5pbWFnZUVsZW1lbnQoKTsKKyAgICAgICAgaWYgKGltYWdl
RWxlbWVudCkKKyAgICAgICAgICAgIGhpdFJlbmRlcmVyID0gaW1hZ2VFbGVtZW50LT5yZW5kZXJl
cigpOworICAgIH0KICAgICBSZW5kZXJPYmplY3QqIHJlbmRlcmVyID0gaGl0UmVuZGVyZXI7CiAg
ICAgd2hpbGUgKHJlbmRlcmVyICYmICFyZW5kZXJlci0+aXNCb2R5KCkgJiYgIXJlbmRlcmVyLT5p
c0RvY3VtZW50RWxlbWVudFJlbmRlcmVyKCkpIHsKICAgICAgICAgaWYgKHJlbmRlcmVyLT5pc1Jl
bmRlckJsb2NrKCkgfHwgcmVuZGVyZXItPmlzSW5saW5lQmxvY2tPcklubGluZVRhYmxlKCkgfHwg
cmVuZGVyZXItPmlzUmVwbGFjZWQoKSkgewo=
</data>
<flag name="review"
          id="381867"
          type_id="1"
          status="+"
          setter="graouts"
    />
          </attachment>
      

    </bug>

</bugzilla>