<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>196600</bug_id>
          
          <creation_ts>2019-04-04 07:42:38 -0700</creation_ts>
          <short_desc>AX: Crash under WebCore::AccessibilityRenderObject::computeAccessibilityIsIgnored()</short_desc>
          <delta_ts>2019-04-04 13:31:40 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Accessibility</component>
          <version>Other</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="chris fleizach">cfleizach</reporter>
          <assigned_to name="chris fleizach">cfleizach</assigned_to>
          <cc>aboxhall</cc>
    
    <cc>apinheiro</cc>
    
    <cc>commit-queue</cc>
    
    <cc>dmazzoni</cc>
    
    <cc>ews-watchlist</cc>
    
    <cc>jcraig</cc>
    
    <cc>jdiggs</cc>
    
    <cc>samuel_white</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1524218</commentid>
    <comment_count>0</comment_count>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2019-04-04 07:42:38 -0700</bug_when>
    <thetext>Crash detected during stress cycling

Exception Type:  EXC_BAD_ACCESS (SIGSEGV)
Exception Subtype: KERN_INVALID_ADDRESS at 0x0000000000000030
VM Region Info: 0x30 is not in any region.  Bytes before following region: 4295655376
      REGION TYPE                      START - END             [ VSIZE] PRT/MAX SHRMOD  REGION DETAIL
      UNUSED SPACE AT START
---&gt;  
      __TEXT                 00000001000a8000-00000001000ac000 [   16K] r-x/r-x SM=COW  ...it.WebContent

Termination Signal: Segmentation fault: 11
Termination Reason: Namespace SIGNAL, Code 0xb
Terminating Process: exc handler [1346]
Triggered by Thread:  0

Thread 0 name:  Dispatch queue: com.apple.main-thread
Thread 0 Crashed:
0   WebCore                       	0x00000001c44007a4 WebCore::AccessibilityRenderObject::computeAccessibilityIsIgnored() const + 184 (/BuildRoot/Library/Caches/com.apple.xbs/Sources/WebCore/WebCore-7607.2.2/rendering/RenderObject.h:932)
1   WebCore                       	0x00000001c44007a4 WebCore::AccessibilityRenderObject::computeAccessibilityIsIgnored() const + 184 (./accessibility/AccessibilityRenderObject.cpp:1197)
2   WebCore                       	0x00000001c43fb460 WebCore::AccessibilityObject::accessibilityIsIgnored() const + 92 (./accessibility/AccessibilityObject.cpp:3342)
3   WebCore                       	0x00000001c43d1274 WebCore::AXObjectCache::getOrCreate(WebCore::RenderObject*) + 784 (./accessibility/AXObjectCache.cpp:637)
4   WebCore                       	0x00000001c43d4110 WebCore::AXObjectCache::frameLoadingEventNotification(WebCore::Frame*, WebCore::AXObjectCache::AXLoadingEvent) + 48 (./accessibility/AXObjectCache.cpp:1352)
5   WebCore                       	0x00000001c4a3f8bc WebCore::FrameLoader::prepareForLoadStart() + 292 (./loader/FrameLoader.cpp:1229)
6   WebCore                       	0x00000001c4a55390 WTF::Function&lt;void ()&gt;::CallableWrapper&lt;WebCore::FrameLoader::continueLoadAfterNavigationPolicy(WebCore::ResourceRequest const&amp;, WebCore::FormState*, WebCore::NavigationPolicyDecision, WebCore::AllowNavigationToInvalidURL)::$_11&gt;::call() + 52 (./loader/FrameLoader.cpp:3432)
7   WebCore                       	0x00000001c4a42a08 WebCore::FrameLoader::continueLoadAfterNavigationPolicy(WebCore::ResourceRequest const&amp;, WebCore::FormState*, WebCore::NavigationPolicyDecision, WebCore::AllowNavigationToInvalidURL) + 1788 (/BuildRoot/Applications/Xcode.app/Contents/Developer/Platforms/iPhoneOS.platform/Developer/SDKs/iPhoneOS12.3.Internal.sdk/usr/local/include/wtf/Function.h:56)
8   WebCore                       	0x00000001c4a5493c WTF::Function&lt;void (WebCore::ResourceRequest&amp;&amp;, WTF::WeakPtr&lt;WebCore::FormState&gt;&amp;&amp;, WebCore::NavigationPolicyDecision)&gt;::CallableWrapper&lt;WebCore::FrameLoader::loadWithDocumentLoader(WebCore::DocumentLoader*, WebCore::FrameLoadType, WTF::RefPtr&lt;WebCore::FormState, WTF::DumbPtrTraits&lt;WebCore::FormState&gt; &gt;&amp;&amp;, WebCore::AllowNavigationToInvalidURL, WebCore::ShouldTreatAsContinuingLoad, WTF::CompletionHandler&lt;void ()&gt;&amp;&amp;)::$_8&gt;::call(WebCore::ResourceRequest&amp;&amp;, WTF::WeakPtr&lt;WebCore::FormState&gt;&amp;&amp;, WebCore::NavigationPolicyDecision) + 48 (./loader/FrameLoader.cpp:1639)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1524219</commentid>
    <comment_count>1</comment_count>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2019-04-04 07:42:54 -0700</bug_when>
    <thetext>&lt;rdar://problem/49572996&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1524220</commentid>
    <comment_count>2</comment_count>
      <attachid>366710</attachid>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2019-04-04 07:47:41 -0700</bug_when>
    <thetext>Created attachment 366710
patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1524392</commentid>
    <comment_count>3</comment_count>
      <attachid>366710</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2019-04-04 13:31:39 -0700</bug_when>
    <thetext>Comment on attachment 366710
patch

Clearing flags on attachment: 366710

Committed r243894: &lt;https://trac.webkit.org/changeset/243894&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1524393</commentid>
    <comment_count>4</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2019-04-04 13:31:40 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>366710</attachid>
            <date>2019-04-04 07:47:41 -0700</date>
            <delta_ts>2019-04-04 13:31:39 -0700</delta_ts>
            <desc>patch</desc>
            <filename>patch</filename>
            <type>text/plain</type>
            <size>2118</size>
            <attacher name="chris fleizach">cfleizach</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJDb3JlL0NoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2Vi
Q29yZS9DaGFuZ2VMb2cJKHJldmlzaW9uIDI0Mzg2OCkKKysrIFNvdXJjZS9XZWJDb3JlL0NoYW5n
ZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE5IEBACisyMDE5LTA0LTA0ICBDaHJpcyBG
bGVpemFjaCAgPGNmbGVpemFjaEBhcHBsZS5jb20+CisKKyAgICAgICAgQVg6IENyYXNoIHVuZGVy
IFdlYkNvcmU6OkFjY2Vzc2liaWxpdHlSZW5kZXJPYmplY3Q6OmNvbXB1dGVBY2Nlc3NpYmlsaXR5
SXNJZ25vcmVkKCkKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dp
P2lkPTE5NjYwMAorICAgICAgICA8cmRhcjovL3Byb2JsZW0vNDk1NzI5OTY+CisKKyAgICAgICAg
UmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAgICAgQXVkaXQgQVggY29kZSB0byBu
b3QgZGVyZWZlcmVuY2UgcmVuZGVyZXIgYmVmb3JlIGNoZWNraW5nIGlmIGl0J3MgbnVsbC4KKyAg
ICAgICAgTm90IGNsZWFyIGhvdyB0byByZXByb2R1Y2UgYXQgdGhpcyB0aW1lLgorCisgICAgICAg
ICogYWNjZXNzaWJpbGl0eS9BY2Nlc3NpYmlsaXR5UmVuZGVyT2JqZWN0LmNwcDoKKyAgICAgICAg
KFdlYkNvcmU6OndlYkFyZWFJc1ByZXNlbnRhdGlvbmFsKToKKyAgICAgICAgKFdlYkNvcmU6OkFj
Y2Vzc2liaWxpdHlSZW5kZXJPYmplY3Q6OmxheW91dENvdW50IGNvbnN0KToKKyAgICAgICAgKFdl
YkNvcmU6OkFjY2Vzc2liaWxpdHlSZW5kZXJPYmplY3Q6OndpZGdldCBjb25zdCk6CisKIDIwMTkt
MDQtMDQgIEFudG9pbmUgUXVpbnQgIDxncmFvdXRzQGFwcGxlLmNvbT4KIAogICAgICAgICBbV2Vi
IEFuaW1hdGlvbnNdIEpTIHdyYXBwZXIgbWF5IGJlIGRlbGV0ZWQgd2hpbGUgYW5pbWF0aW9uIGlz
IHlldCB0byBkaXNwYXRjaCBpdHMgZmluaXNoIGV2ZW50CkluZGV4OiBTb3VyY2UvV2ViQ29yZS9h
Y2Nlc3NpYmlsaXR5L0FjY2Vzc2liaWxpdHlSZW5kZXJPYmplY3QuY3BwCj09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0t
IFNvdXJjZS9XZWJDb3JlL2FjY2Vzc2liaWxpdHkvQWNjZXNzaWJpbGl0eVJlbmRlck9iamVjdC5j
cHAJKHJldmlzaW9uIDI0Mzc4MSkKKysrIFNvdXJjZS9XZWJDb3JlL2FjY2Vzc2liaWxpdHkvQWNj
ZXNzaWJpbGl0eVJlbmRlck9iamVjdC5jcHAJKHdvcmtpbmcgY29weSkKQEAgLTExNTYsNyArMTE1
Niw3IEBACiAgICAgCiBzdGF0aWMgYm9vbCB3ZWJBcmVhSXNQcmVzZW50YXRpb25hbChSZW5kZXJP
YmplY3QqIHJlbmRlcmVyKQogewotICAgIGlmICghaXM8UmVuZGVyVmlldz4oKnJlbmRlcmVyKSkK
KyAgICBpZiAoIXJlbmRlcmVyIHx8ICFpczxSZW5kZXJWaWV3PigqcmVuZGVyZXIpKQogICAgICAg
ICByZXR1cm4gZmFsc2U7CiAgICAgCiAgICAgaWYgKGF1dG8gb3duZXJFbGVtZW50ID0gcmVuZGVy
ZXItPmRvY3VtZW50KCkub3duZXJFbGVtZW50KCkpCkBAIC0xNDQ1LDcgKzE0NDUsNyBAQAogICAg
IAogaW50IEFjY2Vzc2liaWxpdHlSZW5kZXJPYmplY3Q6OmxheW91dENvdW50KCkgY29uc3QKIHsK
LSAgICBpZiAoIWlzPFJlbmRlclZpZXc+KCptX3JlbmRlcmVyKSkKKyAgICBpZiAoIW1fcmVuZGVy
ZXIgfHwgIWlzPFJlbmRlclZpZXc+KCptX3JlbmRlcmVyKSkKICAgICAgICAgcmV0dXJuIDA7CiAg
ICAgcmV0dXJuIGRvd25jYXN0PFJlbmRlclZpZXc+KCptX3JlbmRlcmVyKS5mcmFtZVZpZXcoKS5s
YXlvdXRDb250ZXh0KCkubGF5b3V0Q291bnQoKTsKIH0KQEAgLTE4MTYsNyArMTgxNiw3IEBACiAK
IFdpZGdldCogQWNjZXNzaWJpbGl0eVJlbmRlck9iamVjdDo6d2lkZ2V0KCkgY29uc3QKIHsKLSAg
ICBpZiAoIWlzPFJlbmRlcldpZGdldD4oKm1fcmVuZGVyZXIpKQorICAgIGlmICghbV9yZW5kZXJl
ciB8fCAhaXM8UmVuZGVyV2lkZ2V0PigqbV9yZW5kZXJlcikpCiAgICAgICAgIHJldHVybiBudWxs
cHRyOwogICAgIHJldHVybiBkb3duY2FzdDxSZW5kZXJXaWRnZXQ+KCptX3JlbmRlcmVyKS53aWRn
ZXQoKTsKIH0K
</data>

          </attachment>
      

    </bug>

</bugzilla>