<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>43270</bug_id>
          
          <creation_ts>2010-07-30 14:13:53 -0700</creation_ts>
          <short_desc>WebBackForwardList::backListAsImmutableArrayWithLimit() can return array with bogus items if limit is large</short_desc>
          <delta_ts>2010-07-30 15:39:18 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>PC</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ada Chan">adachan</reporter>
          <assigned_to name="Ada Chan">adachan</assigned_to>
          <cc>sullivan</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>258375</commentid>
    <comment_count>0</comment_count>
    <who name="Ada Chan">adachan</who>
    <bug_when>2010-07-30 14:13:53 -0700</bug_when>
    <thetext>In one example, we pass in max size_t value as the limit, and the line 

unsigned i = std::max&lt;int&gt;(m_current - limit, 0)

returns a positive integer that&apos;s &gt;= m_current, when we expect it to be 0.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>258392</commentid>
    <comment_count>1</comment_count>
      <attachid>63103</attachid>
    <who name="Ada Chan">adachan</who>
    <bug_when>2010-07-30 14:42:12 -0700</bug_when>
    <thetext>Created attachment 63103
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>258424</commentid>
    <comment_count>2</comment_count>
      <attachid>63103</attachid>
    <who name="John Sullivan">sullivan</who>
    <bug_when>2010-07-30 15:36:36 -0700</bug_when>
    <thetext>Comment on attachment 63103
Patch

Much cleaner.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>258426</commentid>
    <comment_count>3</comment_count>
    <who name="Ada Chan">adachan</who>
    <bug_when>2010-07-30 15:39:18 -0700</bug_when>
    <thetext>Fixed in r64381.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>63103</attachid>
            <date>2010-07-30 14:42:12 -0700</date>
            <delta_ts>2010-07-30 15:36:36 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>43270.patch.txt</filename>
            <type>text/plain</type>
            <size>1630</size>
            <attacher name="Ada Chan">adachan</attacher>
            
              <data encoding="base64">SW5kZXg6IFdlYktpdDIvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFdlYktpdDIvQ2hhbmdlTG9n
CShyZXZpc2lvbiA2NDM3NCkKKysrIFdlYktpdDIvQ2hhbmdlTG9nCSh3b3JraW5nIGNvcHkpCkBA
IC0xLDMgKzEsMTMgQEAKKzIwMTAtMDctMzAgIEFkYSBDaGFuICA8YWRhY2hhbkBhcHBsZS5jb20+
CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAgICAgRml4IGlz
c3VlIHdpdGggcG9wdWxhdGluZyB0aGUgYmFjayBsaXN0IHdoZW4gbGltaXQgaXMgYSBodWdlIG51
bWJlci4KKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTQz
MjcwCisKKyAgICAgICAgKiBVSVByb2Nlc3MvV2ViQmFja0ZvcndhcmRMaXN0LmNwcDoKKyAgICAg
ICAgKFdlYktpdDo6V2ViQmFja0ZvcndhcmRMaXN0OjpiYWNrTGlzdEFzSW1tdXRhYmxlQXJyYXlX
aXRoTGltaXQpOgorCiAyMDEwLTA3LTMwICBBbmRlcnMgQ2FybHNzb24gIDxhbmRlcnNjYUBhcHBs
ZS5jb20+CiAKICAgICAgICAgUmV2aWV3ZWQgYnkgU2FtIFdlaW5pZy4KSW5kZXg6IFdlYktpdDIv
VUlQcm9jZXNzL1dlYkJhY2tGb3J3YXJkTGlzdC5jcHAKPT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gV2ViS2l0Mi9V
SVByb2Nlc3MvV2ViQmFja0ZvcndhcmRMaXN0LmNwcAkocmV2aXNpb24gNjQzNzQpCisrKyBXZWJL
aXQyL1VJUHJvY2Vzcy9XZWJCYWNrRm9yd2FyZExpc3QuY3BwCSh3b3JraW5nIGNvcHkpCkBAIC0x
ODAsMTIgKzE4MCwxNCBAQCBzdGF0aWMgdm9pZCB3ZWJCYWNrRm9yd2FyZExpc3RJdGVtRGVyZWYo
CiAKIFBhc3NSZWZQdHI8SW1tdXRhYmxlQXJyYXk+IFdlYkJhY2tGb3J3YXJkTGlzdDo6YmFja0xp
c3RBc0ltbXV0YWJsZUFycmF5V2l0aExpbWl0KHVuc2lnbmVkIGxpbWl0KQogewotICAgIHVuc2ln
bmVkIHNpemUgPSBzdGQ6Om1pbihzdGF0aWNfY2FzdDx1bnNpZ25lZD4oYmFja0xpc3RDb3VudCgp
KSwgbGltaXQpOworICAgIHVuc2lnbmVkIGJhY2tMaXN0U2l6ZSA9IHN0YXRpY19jYXN0PHVuc2ln
bmVkPihiYWNrTGlzdENvdW50KCkpOworICAgIHVuc2lnbmVkIHNpemUgPSBzdGQ6Om1pbihiYWNr
TGlzdFNpemUsIGxpbWl0KTsKICAgICBpZiAoIXNpemUpCiAgICAgICAgIHJldHVybiBJbW11dGFi
bGVBcnJheTo6Y3JlYXRlKCk7CiAKICAgICB2b2lkKiogYXJyYXkgPSBuZXcgdm9pZCpbc2l6ZV07
Ci0gICAgZm9yICh1bnNpZ25lZCBpID0gc3RkOjptYXg8aW50PihtX2N1cnJlbnQgLSBsaW1pdCwg
MCksIGogPSAwOyBpIDwgbV9jdXJyZW50OyArK2ksICsraikgeworICAgIEFTU0VSVChiYWNrTGlz
dFNpemUgPj0gc2l6ZSk7CisgICAgZm9yICh1bnNpZ25lZCBpID0gYmFja0xpc3RTaXplIC0gc2l6
ZSwgaiA9IDA7IGkgPCBiYWNrTGlzdFNpemU7ICsraSwgKytqKSB7CiAgICAgICAgIFdlYkJhY2tG
b3J3YXJkTGlzdEl0ZW0qIGl0ZW0gPSBtX2VudHJpZXNbaV0uZ2V0KCk7CiAgICAgICAgIGl0ZW0t
PnJlZigpOwogICAgICAgICBhcnJheVtqXSA9IGl0ZW07Cg==
</data>
<flag name="review"
          id="51404"
          type_id="1"
          status="+"
          setter="sullivan"
    />
          </attachment>
      

    </bug>

</bugzilla>