<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>279649</bug_id>
          
          <creation_ts>2024-09-12 23:34:37 -0700</creation_ts>
          <short_desc>[cairo] ASSERTION FAILED: destSize &gt; 0 in WebCore::Cairo::calculateSubsurfaceRect</short_desc>
          <delta_ts>2024-09-17 13:53:15 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Platform</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Fujii Hironori">fujii</reporter>
          <assigned_to name="Fujii Hironori">fujii</assigned_to>
          <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>2059908</commentid>
    <comment_count>0</comment_count>
    <who name="Fujii Hironori">fujii</who>
    <bug_when>2024-09-12 23:34:37 -0700</bug_when>
    <thetext>Window port Debug builds are crashing:

  imported/w3c/web-platform-tests/html/canvas/element/drawing-images-to-the-canvas/2d.drawImage.negativedest.html [ Crash ]
  imported/w3c/web-platform-tests/html/canvas/element/drawing-images-to-the-canvas/2d.drawImage.negativedir.html [ Crash ]


ASSERTION FAILED: destSize &gt; 0
C:\webkit\wc\Source\WebCore\platform/graphics/cairo/CairoOperations.cpp(875) : auto WebCore::Cairo::calculateSubsurfaceRect(FloatRect &amp;, FloatRect &amp;, const IntSize &amp;, FloatSize &amp;)::(anonymous class)::operator()(float &amp;, float &amp;, float &amp;, float &amp;, float, float &amp;) const
1   00007FFF6843EFD0 WebCore::Cairo::calculateSubsurfaceRect::&lt;lambda_0&gt;::operator()
2   00007FFF684397B7 WebCore::Cairo::calculateSubsurfaceRect
3   00007FFF68438EAD WebCore::Cairo::drawSurface
4   00007FFF68438A42 WebCore::Cairo::drawPlatformImage
5   00007FFF68449CCE WebCore::GraphicsContextCairo::drawNativeImageInternal
6   00007FFF6834B746 WebCore::GraphicsContext::drawImageBuffer
7   00007FFF68484DC1 WebCore::DisplayList::DrawImageBuffer::apply
8   00007FFF61759734 WebKit::RemoteDisplayListRecorder::handleItem&lt;WebCore::DisplayList::DrawImageBuffer,WebCore::ImageBuffer &amp;&gt;
9   00007FFF61743CBE WebKit::RemoteDisplayListRecorder::drawImageBuffer
10  00007FFF615C6F8B IPC::callMemberFunction&lt;WebKit::RemoteDisplayListRecorder,WebKit::RemoteDisplayListRecorder,void (WTF::ObjectIdentifierGeneric&lt;WebCore::RenderingResourceIdentifierType,WTF::ObjectIdentifierThreadSafeAccessTraits&lt;unsigned long long&gt;,unsigned long long,1&gt;, const WebCore::FloatRect &amp;, const WebCore::FloatRect &amp;, WebCore::ImagePaintingOptions),std::tuple&lt;WTF::ObjectIdentifierGeneric&lt;WebCore::RenderingResourceIdentifierType,WTF::ObjectIdentifierThreadSafeAccessTraits&lt;unsigned long long&gt;,unsigned long long,1&gt;,WebCore::FloatRect,WebCore::FloatRect,WebCore::ImagePaintingOptions&gt; &gt;::&lt;lambda_1&gt;::operator()&lt;WTF::ObjectIdentifierGeneric&lt;WebCore::RenderingResourceIdentifierType,WTF::ObjectIdentifierThreadSafeAccessTraits&lt;unsigned long long&gt;,unsigned long long,1&gt;,WebCore::FloatRect,WebCore::FloatRect,WebCore::ImagePaintingOptions&gt;
11  00007FFF615C6EB0 std::invoke&lt;`lambda at C:\webkit\wc\Source\WebKit\Platform\IPC\HandleMessage.h:134:9&apos;,WTF::ObjectIdentifierGeneric&lt;WebCore::RenderingResourceIdentifierType,WTF::ObjectIdentifierThreadSafeAccessTraits&lt;unsigned long long&gt;,unsigned long long,1&gt;,WebCore::FloatRect,WebCore::FloatRect,WebCore::ImagePaintingOptions&gt;
12  00007FFF615C6E5B std::_Apply_impl&lt;`lambda at C:\webkit\wc\Source\WebKit\Platform\IPC\HandleMessage.h:134:9&apos;,std::tuple&lt;WTF::ObjectIdentifierGeneric&lt;WebCore::RenderingResourceIdentifierType,WTF::ObjectIdentifierThreadSafeAccessTraits&lt;unsigned long long&gt;,unsigned long long,1&gt;,WebCore::FloatRect,WebCore::FloatRect,WebCore::ImagePaintingOptions&gt;,0,1,2,3&gt;
13  00007FFF615C6DE2 std::apply&lt;`lambda at C:\webkit\wc\Source\WebKit\Platform\IPC\HandleMessage.h:134:9&apos;,std::tuple&lt;WTF::ObjectIdentifierGeneric&lt;WebCore::RenderingResourceIdentifierType,WTF::ObjectIdentifierThreadSafeAccessTraits&lt;unsigned long long&gt;,unsigned long long,1&gt;,WebCore::FloatRect,WebCore::FloatRect,WebCore::ImagePaintingOptions&gt; &gt;
14  00007FFF615C60CF IPC::callMemberFunction&lt;WebKit::RemoteDisplayListRecorder,WebKit::RemoteDisplayListRecorder,void (WTF::ObjectIdentifierGeneric&lt;WebCore::RenderingResourceIdentifierType,WTF::ObjectIdentifierThreadSafeAccessTraits&lt;unsigned long long&gt;,unsigned long long,1&gt;, const WebCore::FloatRect &amp;, const WebCore::FloatRect &amp;, WebCore::ImagePaintingOptions),std::tuple&lt;WTF::ObjectIdentifierGeneric&lt;WebCore::RenderingResourceIdentifierType,WTF::ObjectIdentifierThreadSafeAccessTraits&lt;unsigned long long&gt;,unsigned long long,1&gt;,WebCore::FloatRect,WebCore::FloatRect,WebCore::ImagePaintingOptions&gt; &gt;
15  00007FFF615A0DF2 IPC::handleMessage&lt;Messages::RemoteDisplayListRecorder::DrawImageBuffer,WebKit::RemoteDisplayListRecorder,WebKit::RemoteDisplayListRecorder,void (WTF::ObjectIdentifierGeneric&lt;WebCore::RenderingResourceIdentifierType,WTF::ObjectIdentifierThreadSafeAccessTraits&lt;unsigned long long&gt;,unsigned long long,1&gt;, const WebCore::FloatRect &amp;, const WebCore::FloatRect &amp;, WebCore::ImagePaintingOptions)&gt;
16  00007FFF61589A7F WebKit::RemoteDisplayListRecorder::didReceiveStreamMessage
17  00007FFF61C89B86 IPC::StreamServerConnection::dispatchStreamMessage
18  00007FFF61C88963 IPC::StreamServerConnection::dispatchStreamMessages
19  00007FFF61C88484 IPC::StreamConnectionWorkQueue::processStreams
20  00007FFF61C8A6EF IPC::StreamConnectionWorkQueue::startProcessingThread::&lt;lambda_2&gt;::operator()
21  00007FFF61C8A697 WTF::Detail::CallableWrapper&lt;`lambda at C:\webkit\wc\Source\WebKit\Platform\IPC\StreamConnectionWorkQueue.cpp:123:17&apos;,void&gt;::call
22  00007FFF5EF66B69 WTF::Function&lt;void ()&gt;::operator()
23  00007FFF6008D9FC WTF::Thread::entryPoint
24  00007FFF60167543 WTF::wtfThreadEntryPoint
25  00007FF844119333 recalloc
26  00007FF84617257D BaseThreadInitThunk
27  00007FF84690AF28 RtlUserThreadStart
Exception thrown at 0x00007FFF5FF3AEB5 (JavaScriptCore.dll) in WebKitGPUProcess.exe: 0xC0000005: Access violation writing location 0x00000000BBADBEEF.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2059909</commentid>
    <comment_count>1</comment_count>
    <who name="Fujii Hironori">fujii</who>
    <bug_when>2024-09-12 23:35:01 -0700</bug_when>
    <thetext>It&apos;s reproducible just by loading
https://wpt.live/html/canvas/element/drawing-images-to-the-canvas/2d.drawImage.negativedest.html
with Windows Debug MiniBrowser.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2060708</commentid>
    <comment_count>2</comment_count>
    <who name="Fujii Hironori">fujii</who>
    <bug_when>2024-09-17 00:35:40 -0700</bug_when>
    <thetext>Pull request: https://github.com/WebKit/WebKit/pull/33756</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2060847</commentid>
    <comment_count>3</comment_count>
    <who name="EWS">ews-feeder</who>
    <bug_when>2024-09-17 13:52:30 -0700</bug_when>
    <thetext>Committed 283797@main (028c2cf49867): &lt;https://commits.webkit.org/283797@main&gt;

Reviewed commits have been landed. Closing PR #33756 and removing active labels.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2060848</commentid>
    <comment_count>4</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2024-09-17 13:53:15 -0700</bug_when>
    <thetext>&lt;rdar://problem/136174675&gt;</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>