<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>205165</bug_id>
          
          <creation_ts>2019-12-12 09:05:14 -0800</creation_ts>
          <short_desc>Uninitialized variables in RenderLayer</short_desc>
          <delta_ts>2019-12-13 00:41:17 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Layout and Rendering</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Carlos Garcia Campos">cgarcia</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>bfulgham</cc>
    
    <cc>esprehn+autocc</cc>
    
    <cc>ews-watchlist</cc>
    
    <cc>fred.wang</cc>
    
    <cc>glenn</cc>
    
    <cc>kondapallykalyan</cc>
    
    <cc>pdr</cc>
    
    <cc>simon.fraser</cc>
    
    <cc>webkit-bug-importer</cc>
    
    <cc>zalan</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1598010</commentid>
    <comment_count>0</comment_count>
    <who name="Carlos Garcia Campos">cgarcia</who>
    <bug_when>2019-12-12 09:05:14 -0800</bug_when>
    <thetext>Caught by valgrind:

==134047== Conditional jump or move depends on uninitialised value(s)
==134047==    at 0x7DD9B96: WebCore::RenderLayer::setIsCSSStackingContext(bool) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x7DE8F7D: WebCore::RenderLayer::RenderLayer(WebCore::RenderLayerModelObject&amp;) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x7E34150: WebCore::RenderLayerModelObject::createLayer() (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x7E34B1B: WebCore::RenderLayerModelObject::styleDidChange(WebCore::StyleDifference, WebCore::RenderStyle const*) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x7D5BD36: WebCore::RenderBox::styleDidChange(WebCore::StyleDifference, WebCore::RenderStyle const*) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x7D5D0AD: WebCore::RenderBlock::styleDidChange(WebCore::StyleDifference, WebCore::RenderStyle const*) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x7D5D417: WebCore::RenderBlockFlow::styleDidChange(WebCore::StyleDifference, WebCore::RenderStyle const*) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x7FBA6D2: WebCore::RenderTreeUpdater::createRenderer(WebCore::Element&amp;, WebCore::RenderStyle&amp;&amp;) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x7FBA961: WebCore::RenderTreeUpdater::updateElementRenderer(WebCore::Element&amp;, WebCore::Style::ElementUpdate const&amp;) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x7FBBFCE: WebCore::RenderTreeUpdater::updateRenderTree(WebCore::ContainerNode&amp;) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x7FBC70A: WebCore::RenderTreeUpdater::commit(std::unique_ptr&lt;WebCore::Style::Update const, std::default_delete&lt;WebCore::Style::Update const&gt; &gt;) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047==    by 0x750BDB5: WebCore::Document::resolveStyle(WebCore::Document::ResolveStyleType) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==134047== 

==133221== Conditional jump or move depends on uninitialised value(s)
==133221==    at 0x7DD9CCF: WebCore::RenderLayer::setIsNormalFlowOnly(bool) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x7DE8F6A: WebCore::RenderLayer::RenderLayer(WebCore::RenderLayerModelObject&amp;) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x7E34150: WebCore::RenderLayerModelObject::createLayer() (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x7E34B1B: WebCore::RenderLayerModelObject::styleDidChange(WebCore::StyleDifference, WebCore::RenderStyle const*) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x7D5BD36: WebCore::RenderBox::styleDidChange(WebCore::StyleDifference, WebCore::RenderStyle const*) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x7D5D0AD: WebCore::RenderBlock::styleDidChange(WebCore::StyleDifference, WebCore::RenderStyle const*) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x7D5D417: WebCore::RenderBlockFlow::styleDidChange(WebCore::StyleDifference, WebCore::RenderStyle const*) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x7FBA6D2: WebCore::RenderTreeUpdater::createRenderer(WebCore::Element&amp;, WebCore::RenderStyle&amp;&amp;) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x7FBA961: WebCore::RenderTreeUpdater::updateElementRenderer(WebCore::Element&amp;, WebCore::Style::ElementUpdate const&amp;) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x7FBBFCE: WebCore::RenderTreeUpdater::updateRenderTree(WebCore::ContainerNode&amp;) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x7FBC70A: WebCore::RenderTreeUpdater::commit(std::unique_ptr&lt;WebCore::Style::Update const, std::default_delete&lt;WebCore::Style::Update const&gt; &gt;) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==    by 0x750BDB5: WebCore::Document::resolveStyle(WebCore::Document::ResolveStyleType) (in /home/cgarcia/src/git/gnome/WebKit/WebKitBuild/Release/lib/libwebkit2gtk-4.0.so.37.42.0)
==133221==</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1598011</commentid>
    <comment_count>1</comment_count>
      <attachid>385499</attachid>
    <who name="Carlos Garcia Campos">cgarcia</who>
    <bug_when>2019-12-12 09:07:04 -0800</bug_when>
    <thetext>Created attachment 385499
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1598277</commentid>
    <comment_count>2</comment_count>
    <who name="Carlos Garcia Campos">cgarcia</who>
    <bug_when>2019-12-13 00:41:01 -0800</bug_when>
    <thetext>Committed r253466: &lt;https://trac.webkit.org/changeset/253466&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1598278</commentid>
    <comment_count>3</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2019-12-13 00:41:17 -0800</bug_when>
    <thetext>&lt;rdar://problem/57905791&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>385499</attachid>
            <date>2019-12-12 09:07:04 -0800</date>
            <delta_ts>2019-12-12 11:04:34 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>wcore-uninitialized-render-layer.diff</filename>
            <type>text/plain</type>
            <size>1351</size>
            <attacher name="Carlos Garcia Campos">cgarcia</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJDb3JlL0NoYW5nZUxvZyBiL1NvdXJjZS9XZWJDb3JlL0No
YW5nZUxvZwppbmRleCAyNWQxNDMzZmE1YS4uMWE1NmJkMGM1MDMgMTAwNjQ0Ci0tLSBhL1NvdXJj
ZS9XZWJDb3JlL0NoYW5nZUxvZworKysgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKQEAgLTEs
MyArMSwxMyBAQAorMjAxOS0xMi0xMiAgQ2FybG9zIEdhcmNpYSBDYW1wb3MgIDxjZ2FyY2lhQGln
YWxpYS5jb20+CisKKyAgICAgICAgVW5pbml0aWFsaXplZCB2YXJpYWJsZXMgaW4gUmVuZGVyTGF5
ZXIKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTIwNTE2
NQorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgICogcmVu
ZGVyaW5nL1JlbmRlckxheWVyLmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OlJlbmRlckxheWVyOjpS
ZW5kZXJMYXllcik6IEluaXRpYWxpemUgbV9pc05vcm1hbEZsb3dPbmx5IGFuZCBtX2lzQ1NTU3Rh
Y2tpbmdDb250ZXh0LgorCiAyMDE5LTEyLTEyICB5b3Vlbm4gZmFibGV0ICA8eW91ZW5uQGFwcGxl
LmNvbT4KIAogICAgICAgICBSZW1vdmUgZGVidWcgQVNTRVJUIGluIFBlZXJDb25uZWN0aW9uQmFj
a2VuZApkaWZmIC0tZ2l0IGEvU291cmNlL1dlYkNvcmUvcmVuZGVyaW5nL1JlbmRlckxheWVyLmNw
cCBiL1NvdXJjZS9XZWJDb3JlL3JlbmRlcmluZy9SZW5kZXJMYXllci5jcHAKaW5kZXggZDg0YWQx
YTFkYWUuLjU0NGYyMDY0OTU2IDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViQ29yZS9yZW5kZXJpbmcv
UmVuZGVyTGF5ZXIuY3BwCisrKyBiL1NvdXJjZS9XZWJDb3JlL3JlbmRlcmluZy9SZW5kZXJMYXll
ci5jcHAKQEAgLTI4Niw2ICsyODYsOCBAQCBzdGF0aWMgVGV4dFN0cmVhbSYgb3BlcmF0b3I8PChU
ZXh0U3RyZWFtJiB0cywgY29uc3QgQ2xpcFJlY3RzJiBjbGlwUmVjdHMpCiBSZW5kZXJMYXllcjo6
UmVuZGVyTGF5ZXIoUmVuZGVyTGF5ZXJNb2RlbE9iamVjdCYgcmVuZGVyZXJMYXllck1vZGVsT2Jq
ZWN0KQogICAgIDogbV9pc1JlbmRlclZpZXdMYXllcihyZW5kZXJlckxheWVyTW9kZWxPYmplY3Qu
aXNSZW5kZXJWaWV3KCkpCiAgICAgLCBtX2ZvcmNlZFN0YWNraW5nQ29udGV4dChyZW5kZXJlckxh
eWVyTW9kZWxPYmplY3QuaXNNZWRpYSgpKQorICAgICwgbV9pc05vcm1hbEZsb3dPbmx5KGZhbHNl
KQorICAgICwgbV9pc0NTU1N0YWNraW5nQ29udGV4dChmYWxzZSkKICAgICAsIG1faXNPcHBvcnR1
bmlzdGljU3RhY2tpbmdDb250ZXh0KGZhbHNlKQogICAgICwgbV96T3JkZXJMaXN0c0RpcnR5KGZh
bHNlKQogICAgICwgbV9ub3JtYWxGbG93TGlzdERpcnR5KHRydWUpCg==
</data>
<flag name="review"
          id="401305"
          type_id="1"
          status="+"
          setter="simon.fraser"
    />
          </attachment>
      

    </bug>

</bugzilla>