<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>46822</bug_id>
          
          <creation_ts>2010-09-29 10:46:30 -0700</creation_ts>
          <short_desc>[GTK] editing/selection/selection-modify-crash.html crashes when run in Xvfb</short_desc>
          <delta_ts>2010-09-29 10:58:47 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKitGTK</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>PC</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>Gtk</keywords>
          <priority>P3</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Martin Robinson">mrobinson</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>cfleizach</cc>
    
    <cc>mario</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>286978</commentid>
    <comment_count>0</comment_count>
    <who name="Martin Robinson">mrobinson</who>
    <bug_when>2010-09-29 10:46:30 -0700</bug_when>
    <thetext>This is the crashing section of code:

AccessibilityObject* objectAndOffsetUnignored(AccessibilityObject* coreObject, int&amp; offset, bool ignoreLinks)
{
    Node* endNode = static_cast&lt;AccessibilityRenderObject*&gt;(coreObject)-&gt;renderer()-&gt;node();
    int endOffset = coreObject-&gt;selection().end().computeOffsetInContainerNode();
    // Indication that something bogus has transpired.
    offset = -1;

    AccessibilityObject* realObject = coreObject;
    if (realObject-&gt;accessibilityIsIgnored())
        realObject = realObject-&gt;parentObjectUnignored();

    if (ignoreLinks &amp;&amp; realObject-&gt;isLink()) &lt;------- Guilty line
        realObject = realObject-&gt;parentObjectUnignored();

    [...]
}

The issue here is that parentObjectUnignored may return null, particularly in the case that the AccessibilityObject is a WebArea.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>286981</commentid>
    <comment_count>1</comment_count>
      <attachid>69218</attachid>
    <who name="Martin Robinson">mrobinson</who>
    <bug_when>2010-09-29 10:50:56 -0700</bug_when>
    <thetext>Created attachment 69218
Patch for this issue</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>286987</commentid>
    <comment_count>2</comment_count>
      <attachid>69218</attachid>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2010-09-29 10:53:59 -0700</bug_when>
    <thetext>Comment on attachment 69218
Patch for this issue

r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>286992</commentid>
    <comment_count>3</comment_count>
    <who name="Martin Robinson">mrobinson</who>
    <bug_when>2010-09-29 10:58:47 -0700</bug_when>
    <thetext>Committed r68665: &lt;http://trac.webkit.org/changeset/68665&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>69218</attachid>
            <date>2010-09-29 10:50:56 -0700</date>
            <delta_ts>2010-09-29 10:53:58 -0700</delta_ts>
            <desc>Patch for this issue</desc>
            <filename>bug-46822-20100929105057.patch</filename>
            <type>text/plain</type>
            <size>4666</size>
            <attacher name="Martin Robinson">mrobinson</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL0NoYW5nZUxvZyBiL0xheW91dFRlc3RzL0NoYW5nZUxv
ZwppbmRleCBkZDY0MDNlOGExM2FjMTAxYjJmOTlhZWExNDhhYjc2NzliN2NhMTc0Li5jYjM1NTgw
YWI3NDA4Y2I4YmE0YjU3MTkxZTdkMWJjMDY5NDc1NTFkIDEwMDY0NAotLS0gYS9MYXlvdXRUZXN0
cy9DaGFuZ2VMb2cKKysrIGIvTGF5b3V0VGVzdHMvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTIgQEAK
KzIwMTAtMDktMjkgIE1hcnRpbiBSb2JpbnNvbiAgPG1yb2JpbnNvbkBpZ2FsaWEuY29tPgorCisg
ICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIFtHVEtdIGVkaXRp
bmcvc2VsZWN0aW9uL3NlbGVjdGlvbi1tb2RpZnktY3Jhc2guaHRtbCBjcmFzaGVzIHdoZW4gcnVu
IGluIFh2ZmIKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lk
PTQ2ODIyCisKKyAgICAgICAgKiBwbGF0Zm9ybS9ndGsvU2tpcHBlZDogVW5za2lwIGEgdGVzdCB3
aGljaCBpcyBubyBsb25nZXIgY3Jhc2hpbmcuCisKIDIwMTAtMDktMjkgIFBoaWxpcHBlIE5vcm1h
bmQgIDxwbm9ybWFuZEBpZ2FsaWEuY29tPgogCiAgICAgICAgIFVucmV2aWV3ZWQsIHVwZGF0ZWQg
YmFzZWxpbmVzIG9mCmRpZmYgLS1naXQgYS9MYXlvdXRUZXN0cy9wbGF0Zm9ybS9ndGsvU2tpcHBl
ZCBiL0xheW91dFRlc3RzL3BsYXRmb3JtL2d0ay9Ta2lwcGVkCmluZGV4IDBmNzRmMjk5MjU0YTUw
MzU3NmIwMWUxYjgwZTM1N2M1ODk3OGM5NDYuLjdhMmUyYzAyODNmZDI3ZTdjNDI5MGY3MWJlMjkw
OGEzM2I3N2RjYjUgMTAwNjQ0Ci0tLSBhL0xheW91dFRlc3RzL3BsYXRmb3JtL2d0ay9Ta2lwcGVk
CisrKyBiL0xheW91dFRlc3RzL3BsYXRmb3JtL2d0ay9Ta2lwcGVkCkBAIC0xMDAxLDcgKzEwMDEs
NiBAQCBlZGl0aW5nL3NlbGVjdGlvbi9zZWxlY3QtZnJvbS10ZXh0ZmllbGQtb3V0d2FyZHMuaHRt
bAogZWRpdGluZy9zZWxlY3Rpb24vc2VsZWN0LW1pc3NpbmctaW1hZ2UuaHRtbAogZWRpdGluZy9z
ZWxlY3Rpb24vc2VsZWN0aW9uLTM3NDgxNjQtZml4Lmh0bWwKIGVkaXRpbmcvc2VsZWN0aW9uL3Nl
bGVjdGlvbi1iYWNrZ3JvdW5kLmh0bWwKLWVkaXRpbmcvc2VsZWN0aW9uL3NlbGVjdGlvbi1tb2Rp
ZnktY3Jhc2guaHRtbAogZWRpdGluZy9zZWxlY3Rpb24vdGFibGUtY2FyZXQtMS5odG1sCiBlZGl0
aW5nL3NlbGVjdGlvbi90YWJsZS1jYXJldC0yLmh0bWwKIGVkaXRpbmcvc2VsZWN0aW9uL3RhYmxl
LWNhcmV0LTMuaHRtbApkaWZmIC0tZ2l0IGEvV2ViQ29yZS9DaGFuZ2VMb2cgYi9XZWJDb3JlL0No
YW5nZUxvZwppbmRleCBjNjYwZTlkNGZiYWIxNWY1YTYzMjk3ZmMxMWQwNmU5MTNiNWM0NzFlLi4x
OTFmOTU5OGUzODJkZGEwZjQwZjA1YjI5M2JhNGU5ZGFkNzNkZGU1IDEwMDY0NAotLS0gYS9XZWJD
b3JlL0NoYW5nZUxvZworKysgYi9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDIxIEBACisy
MDEwLTA5LTI5ICBNYXJ0aW4gUm9iaW5zb24gIDxtcm9iaW5zb25AaWdhbGlhLmNvbT4KKworICAg
ICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBbR1RLXSBlZGl0aW5n
L3NlbGVjdGlvbi9zZWxlY3Rpb24tbW9kaWZ5LWNyYXNoLmh0bWwgY3Jhc2hlcyB3aGVuIHJ1biBp
biBYdmZiCisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD00
NjgyMgorCisgICAgICAgIFdoZW4gcGFyZW50T2JqZWN0VW5pZ25vcmVkIHJldHVybnMgbnVsbCBp
biBvYmplY3RBbmRPZmZzZXRVbmlnbm9yZWQgY29uc2lkZXIgdGhhdAorICAgICAgICBhIGZhaWx1
cmUgY2FzZS4gSGFuZGxlIHRoaXMgZmFpbHVyZSBhcHByb3ByaWF0ZWx5IGF0IGFsbCBjYWxsIHNp
dGVzLgorCisgICAgICAgICogYWNjZXNzaWJpbGl0eS9ndGsvQWNjZXNzaWJpbGl0eU9iamVjdFdy
YXBwZXJBdGsuY3BwOgorICAgICAgICAod2Via2l0X2FjY2Vzc2libGVfdGV4dF9nZXRfY2FyZXRf
b2Zmc2V0KTogSGFuZGxlIHRoZSBmYWlsdXJlIG9mIG9iamVjdEFuZE9mZnNldFVuaWdub3JlZC4K
KyAgICAgICAgKG9iamVjdEFuZE9mZnNldFVuaWdub3JlZCk6IEFsd2F5cyBjaGVjayB0aGUgcmV0
dXJuIHZhbHVlIG9mIHBhcmVudE9iamVjdFVuaWdub3JlZCBhbmQKKyAgICAgICAgcmV0dXJuIDAg
dG8gaW5kaWNhdGUgZmFpbHVyZSB3aGVuIHRoYXQgaGFwcGVucy4KKyAgICAgICAgKiBlZGl0aW5n
L2d0ay9TZWxlY3Rpb25Db250cm9sbGVyR3RrLmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OlNlbGVj
dGlvbkNvbnRyb2xsZXI6Om5vdGlmeUFjY2Vzc2liaWxpdHlGb3JTZWxlY3Rpb25DaGFuZ2UpOiBI
YW5kbGUgdGhlIGZhaWx1cmUKKyAgICAgICAgY2FzZSBvZiBvYmplY3RBbmRPZmZzZXRVbmlnbm9y
ZWQuCisKIDIwMTAtMDktMjkgIFBoaWxpcHBlIE5vcm1hbmQgIDxwbm9ybWFuZEBpZ2FsaWEuY29t
PgogCiAgICAgICAgIFJldmlld2VkIGJ5IEd1c3Rhdm8gTm9yb25oYSBTaWx2YS4KZGlmZiAtLWdp
dCBhL1dlYkNvcmUvYWNjZXNzaWJpbGl0eS9ndGsvQWNjZXNzaWJpbGl0eU9iamVjdFdyYXBwZXJB
dGsuY3BwIGIvV2ViQ29yZS9hY2Nlc3NpYmlsaXR5L2d0ay9BY2Nlc3NpYmlsaXR5T2JqZWN0V3Jh
cHBlckF0ay5jcHAKaW5kZXggMzU3NWFmZThmNzNjOTQ5Mjk5OGNmZTI4Y2E2YjA0MzJmYjM4OTlj
My4uYzlkMTNjYzFlYjBiOTljMTNiNzU1Mzc5ZmFlMjY2Y2IzNzVjMGI4NSAxMDA2NDQKLS0tIGEv
V2ViQ29yZS9hY2Nlc3NpYmlsaXR5L2d0ay9BY2Nlc3NpYmlsaXR5T2JqZWN0V3JhcHBlckF0ay5j
cHAKKysrIGIvV2ViQ29yZS9hY2Nlc3NpYmlsaXR5L2d0ay9BY2Nlc3NpYmlsaXR5T2JqZWN0V3Jh
cHBlckF0ay5jcHAKQEAgLTEwMzIsNyArMTAzMiw4IEBAIHN0YXRpYyBnaW50IHdlYmtpdF9hY2Nl
c3NpYmxlX3RleHRfZ2V0X2NhcmV0X29mZnNldChBdGtUZXh0KiB0ZXh0KQogCiAgICAgaW50IG9m
ZnNldDsKICAgICAvLyBEb24ndCBpZ25vcmUgbGlua3MgaWYgdGhlIG9mZnNldCBpcyBiZWluZyBy
ZXF1ZXN0ZWQgZm9yIGEgbGluay4KLSAgICBvYmplY3RBbmRPZmZzZXRVbmlnbm9yZWQoZm9jdXNl
ZE9iamVjdCwgb2Zmc2V0LCAhY29yZU9iamVjdC0+aXNMaW5rKCkpOworICAgIGlmICghb2JqZWN0
QW5kT2Zmc2V0VW5pZ25vcmVkKGZvY3VzZWRPYmplY3QsIG9mZnNldCwgIWNvcmVPYmplY3QtPmlz
TGluaygpKSkKKyAgICAgICAgcmV0dXJuIDA7CiAKICAgICAvLyBUT0RPOiBWZXJpZnkgdGhpcyBm
b3IgUlRMIHRleHQuCiAgICAgcmV0dXJuIG9mZnNldDsKQEAgLTIxNzksOSArMjE4MCwxMyBAQCBB
Y2Nlc3NpYmlsaXR5T2JqZWN0KiBvYmplY3RBbmRPZmZzZXRVbmlnbm9yZWQoQWNjZXNzaWJpbGl0
eU9iamVjdCogY29yZU9iamVjdCwgaQogICAgIEFjY2Vzc2liaWxpdHlPYmplY3QqIHJlYWxPYmpl
Y3QgPSBjb3JlT2JqZWN0OwogICAgIGlmIChyZWFsT2JqZWN0LT5hY2Nlc3NpYmlsaXR5SXNJZ25v
cmVkKCkpCiAgICAgICAgIHJlYWxPYmplY3QgPSByZWFsT2JqZWN0LT5wYXJlbnRPYmplY3RVbmln
bm9yZWQoKTsKKyAgICBpZiAoIXJlYWxPYmplY3QpCisgICAgICAgIHJldHVybiAwOwogCiAgICAg
aWYgKGlnbm9yZUxpbmtzICYmIHJlYWxPYmplY3QtPmlzTGluaygpKQogICAgICAgICByZWFsT2Jq
ZWN0ID0gcmVhbE9iamVjdC0+cGFyZW50T2JqZWN0VW5pZ25vcmVkKCk7CisgICAgaWYgKCFyZWFs
T2JqZWN0KQorICAgICAgICByZXR1cm4gMDsKIAogICAgIE5vZGUqIG5vZGUgPSBzdGF0aWNfY2Fz
dDxBY2Nlc3NpYmlsaXR5UmVuZGVyT2JqZWN0Kj4ocmVhbE9iamVjdCktPnJlbmRlcmVyKCktPm5v
ZGUoKTsKICAgICBpZiAobm9kZSkgewpkaWZmIC0tZ2l0IGEvV2ViQ29yZS9lZGl0aW5nL2d0ay9T
ZWxlY3Rpb25Db250cm9sbGVyR3RrLmNwcCBiL1dlYkNvcmUvZWRpdGluZy9ndGsvU2VsZWN0aW9u
Q29udHJvbGxlckd0ay5jcHAKaW5kZXggOWQ1MmMxYWM5Yjg5NjdiYTRjYjY3M2Y0YjY4MjllNzFi
ZjY1OGE5Mi4uNTYyNjExMDYxODQ5YzQ0NDBiZmQyYmFjYmQyZTJkNDY2YTRmMzhmOSAxMDA2NDQK
LS0tIGEvV2ViQ29yZS9lZGl0aW5nL2d0ay9TZWxlY3Rpb25Db250cm9sbGVyR3RrLmNwcAorKysg
Yi9XZWJDb3JlL2VkaXRpbmcvZ3RrL1NlbGVjdGlvbkNvbnRyb2xsZXJHdGsuY3BwCkBAIC00MSw2
ICs0MSw5IEBAIHZvaWQgU2VsZWN0aW9uQ29udHJvbGxlcjo6bm90aWZ5QWNjZXNzaWJpbGl0eUZv
clNlbGVjdGlvbkNoYW5nZSgpCiAgICAgICAgIGludCBvZmZzZXQ7CiAgICAgICAgIC8vIEFsd2F5
cyByZXBvcnQgdGhlIGV2ZW50cyB3LnIudC4gdGhlIG5vbi1saW5rZWQgdW5pZ25vcmVkIHBhcmVu
dC4gKGkuZS4gaWdub3JlTGlua3MgPT0gdHJ1ZSkKICAgICAgICAgQWNjZXNzaWJpbGl0eU9iamVj
dCogb2JqZWN0ID0gb2JqZWN0QW5kT2Zmc2V0VW5pZ25vcmVkKGFjY2Vzc2liaWxpdHlPYmplY3Qs
IG9mZnNldCwgdHJ1ZSk7CisgICAgICAgIGlmICghb2JqZWN0KQorICAgICAgICAgICAgcmV0dXJu
OworCiAgICAgICAgIEF0a09iamVjdCogd3JhcHBlciA9IG9iamVjdC0+d3JhcHBlcigpOwogICAg
ICAgICBpZiAoQVRLX0lTX1RFWFQod3JhcHBlcikpIHsKICAgICAgICAgICAgIGdfc2lnbmFsX2Vt
aXRfYnlfbmFtZSh3cmFwcGVyLCAidGV4dC1jYXJldC1tb3ZlZCIsIG9mZnNldCk7Cg==
</data>
<flag name="review"
          id="58871"
          type_id="1"
          status="+"
          setter="cfleizach"
    />
          </attachment>
      

    </bug>

</bugzilla>