<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>51432</bug_id>
          
          <creation_ts>2010-12-21 16:43:00 -0800</creation_ts>
          <short_desc>[chromium] Render surfaces with empty content rects cause crashes</short_desc>
          <delta_ts>2010-12-22 10:38:09 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebCore Misc.</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>All</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Vangelis Kokkevis">vangelis</reporter>
          <assigned_to name="Vangelis Kokkevis">vangelis</assigned_to>
          <cc>kbr</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>325266</commentid>
    <comment_count>0</comment_count>
    <who name="Vangelis Kokkevis">vangelis</who>
    <bug_when>2010-12-21 16:43:00 -0800</bug_when>
    <thetext>RenderSurfaceChromium&apos;s that have a zero content rect don&apos;t have a texture associated with them.  In RenderSurfaceChromium::draw() we need to check for a NULL m_contentsTexture before trying to bind the texture and render the surface.

The crash can trivially be reproduced by going to:

www.boxee.tv</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>325329</commentid>
    <comment_count>1</comment_count>
      <attachid>77180</attachid>
    <who name="Vangelis Kokkevis">vangelis</who>
    <bug_when>2010-12-21 19:06:58 -0800</bug_when>
    <thetext>Created attachment 77180
Proposed patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>325526</commentid>
    <comment_count>2</comment_count>
      <attachid>77180</attachid>
    <who name="Kenneth Russell">kbr</who>
    <bug_when>2010-12-22 09:43:23 -0800</bug_when>
    <thetext>Comment on attachment 77180
Proposed patch

View in context: https://bugs.webkit.org/attachment.cgi?id=77180&amp;action=review

Looks fine. One small typo.

&gt; LayoutTests/platform/chromium/compositing/empty-render-surface-crasher.html:27
&gt; +&lt;p&gt;This page tests that an empty render surface does not crash as reporterd in &lt;a href=&apos;https://bugs.webkit.org/show_bug.cgi?id=51432&apos;&gt;this bug&lt;/a&gt;. Pass if this does not crash.&lt;/p&gt;

Typo: reporterd -&gt; reported</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>325559</commentid>
    <comment_count>3</comment_count>
    <who name="Vangelis Kokkevis">vangelis</who>
    <bug_when>2010-12-22 10:37:32 -0800</bug_when>
    <thetext>Committed r74484: &lt;http://trac.webkit.org/changeset/74484&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>325561</commentid>
    <comment_count>4</comment_count>
    <who name="Vangelis Kokkevis">vangelis</who>
    <bug_when>2010-12-22 10:38:09 -0800</bug_when>
    <thetext>(In reply to comment #2)
&gt; (From update of attachment 77180 [details])
&gt; View in context: https://bugs.webkit.org/attachment.cgi?id=77180&amp;action=review
&gt; 
&gt; Looks fine. One small typo.
&gt; 
&gt; &gt; LayoutTests/platform/chromium/compositing/empty-render-surface-crasher.html:27
&gt; &gt; +&lt;p&gt;This page tests that an empty render surface does not crash as reporterd in &lt;a href=&apos;https://bugs.webkit.org/show_bug.cgi?id=51432&apos;&gt;this bug&lt;/a&gt;. Pass if this does not crash.&lt;/p&gt;
&gt; 
&gt; Typo: reporterd -&gt; reported

Ooops! Thanks.  Fixed typo and landed.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>77180</attachid>
            <date>2010-12-21 19:06:58 -0800</date>
            <delta_ts>2010-12-22 09:43:23 -0800</delta_ts>
            <desc>Proposed patch</desc>
            <filename>emptyRenderSurface_51432.txt</filename>
            <type>text/plain</type>
            <size>4298</size>
            <attacher name="Vangelis Kokkevis">vangelis</attacher>
            
              <data encoding="base64">SW5kZXg6IFdlYkNvcmUvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFdlYkNvcmUvQ2hhbmdlTG9n
CShyZXZpc2lvbiA3NDQ0OCkKKysrIFdlYkNvcmUvQ2hhbmdlTG9nCSh3b3JraW5nIGNvcHkpCkBA
IC0xLDMgKzEsMTUgQEAKKzIwMTAtMTItMjEgIFZhbmdlbGlzIEtva2tldmlzICA8dmFuZ2VsaXNA
Y2hyb21pdW0ub3JnPgorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisg
ICAgICAgIFtjaHJvbWl1bV0gRml4aW5nIGNyYXNoIHdpdGggZW1wdHkgcmVuZGVyIHN1cmZhY2Vz
LgorICAgICAgICBodHRwczovL2J1Z3Mud2Via2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9NTE0MzIK
KworICAgICAgICBUZXN0OiBwbGF0Zm9ybS9jaHJvbWl1bS9jb21wb3NpdGluZy9lbXB0eS1yZW5k
ZXItc3VyZmFjZS1jcmFzaGVyLmh0bWwKKworICAgICAgICAqIHBsYXRmb3JtL2dyYXBoaWNzL2No
cm9taXVtL1JlbmRlclN1cmZhY2VDaHJvbWl1bS5jcHA6CisgICAgICAgIChXZWJDb3JlOjpSZW5k
ZXJTdXJmYWNlQ2hyb21pdW06OmRyYXcpOgorCiAyMDEwLTEyLTIxICBSeW9zdWtlIE5pd2EgIDxy
bml3YUB3ZWJraXQub3JnPgogCiAgICAgICAgIFVucmV2aWV3ZWQgYnVpbGQgZml4IGZvciByNzQ0
NDcuCkluZGV4OiBXZWJDb3JlL3BsYXRmb3JtL2dyYXBoaWNzL2Nocm9taXVtL1JlbmRlclN1cmZh
Y2VDaHJvbWl1bS5jcHAKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gV2ViQ29yZS9wbGF0Zm9ybS9ncmFwaGljcy9j
aHJvbWl1bS9SZW5kZXJTdXJmYWNlQ2hyb21pdW0uY3BwCShyZXZpc2lvbiA3NDQ0MykKKysrIFdl
YkNvcmUvcGxhdGZvcm0vZ3JhcGhpY3MvY2hyb21pdW0vUmVuZGVyU3VyZmFjZUNocm9taXVtLmNw
cAkod29ya2luZyBjb3B5KQpAQCAtMTM1LDcgKzEzNSw3IEBAIGJvb2wgUmVuZGVyU3VyZmFjZUNo
cm9taXVtOjpwcmVwYXJlQ29udGUKIAogdm9pZCBSZW5kZXJTdXJmYWNlQ2hyb21pdW06OmRyYXco
KQogewotICAgIGlmIChtX3NraXBzRHJhdykKKyAgICBpZiAobV9za2lwc0RyYXcgfHwgIW1fY29u
dGVudHNUZXh0dXJlKQogICAgICAgICByZXR1cm47CiAKICAgICBtX2NvbnRlbnRzVGV4dHVyZS0+
YmluZFRleHR1cmUoKTsKSW5kZXg6IExheW91dFRlc3RzL0NoYW5nZUxvZwo9PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0t
LSBMYXlvdXRUZXN0cy9DaGFuZ2VMb2cJKHJldmlzaW9uIDc0NDQ4KQorKysgTGF5b3V0VGVzdHMv
Q2hhbmdlTG9nCSh3b3JraW5nIGNvcHkpCkBAIC0xLDMgKzEsMTUgQEAKKzIwMTAtMTItMjEgIFZh
bmdlbGlzIEtva2tldmlzICA8dmFuZ2VsaXNAY2hyb21pdW0ub3JnPgorCisgICAgICAgIFJldmll
d2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIFtjaHJvbWl1bV0gRW5hYmxpbmcgbGF5
b3V0IHRlc3RzIGluIHBsYXRmb3JtL2Nocm9taXVtL2NvbXBvc2l0aW5nCisgICAgICAgIGFuZCBh
ZGRpbmcgbmV3IGxheW91dCB0ZXN0IHRvIGNoZWNrIGZvciBjcmFzaCBvbiBlbXB0eSByZW5kZXIg
c3VyZmFjZXMuCisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9p
ZD01MTQzMgorCisgICAgICAgICogcGxhdGZvcm0vY2hyb21pdW0tZ3B1L3Rlc3RfZXhwZWN0YXRp
b25zLnR4dDoKKyAgICAgICAgKiBwbGF0Zm9ybS9jaHJvbWl1bS9jb21wb3NpdGluZy9lbXB0eS1y
ZW5kZXItc3VyZmFjZS1jcmFzaGVyLWV4cGVjdGVkLnR4dDogQWRkZWQuCisgICAgICAgICogcGxh
dGZvcm0vY2hyb21pdW0vY29tcG9zaXRpbmcvZW1wdHktcmVuZGVyLXN1cmZhY2UtY3Jhc2hlci5o
dG1sOiBBZGRlZC4KKwogMjAxMC0xMi0yMSAgRGFuIEJlcm5zdGVpbiAgPG1pdHpAYXBwbGUuY29t
PgogCiAgICAgICAgIFJldmlld2VkIGJ5IEpvaG4gU3VsbGl2YW4uCkluZGV4OiBMYXlvdXRUZXN0
cy9wbGF0Zm9ybS9jaHJvbWl1bS1ncHUvdGVzdF9leHBlY3RhdGlvbnMudHh0Cj09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0K
LS0tIExheW91dFRlc3RzL3BsYXRmb3JtL2Nocm9taXVtLWdwdS90ZXN0X2V4cGVjdGF0aW9ucy50
eHQJKHJldmlzaW9uIDc0NDQzKQorKysgTGF5b3V0VGVzdHMvcGxhdGZvcm0vY2hyb21pdW0tZ3B1
L3Rlc3RfZXhwZWN0YXRpb25zLnR4dAkod29ya2luZyBjb3B5KQpAQCAtNTAsNiArNTAsOCBAQCBX
T05URklYIFNLSVAgOiB3bWwgPSBQQVNTIEZBSUwKIC8vIEZJWE1FOiByZW1vdmUgdGhlIEZBSUwg
ZnJvbSB0aGUgZm9sbG93aW5nIGxpbmUuCiBCVUdOT05FIDogY29tcG9zaXRpbmcgPSBQQVNTIEZB
SUwKIAorcGxhdGZvcm0vY2hyb21pdW0vY29tcG9zaXRpbmcgPSBQQVNTCisKIC8vIFVuc2tpcCB0
aGUgY2FudmFzIHRlc3RzIG9uIFdpbiBhbmQgTGludXggb25seSAoc2luY2UgTWFjIGRvZXMgbm90
IHN1cHBvcnQKIC8vIGFjY2VsZXJhdGVkIDJEIGNhbnZhcyB5ZXQpLgogQlVHTk9ORSBXSU4gTElO
VVggOiBmYXN0L2NhbnZhcyA9IFBBU1MKSW5kZXg6IExheW91dFRlc3RzL3BsYXRmb3JtL2Nocm9t
aXVtL2NvbXBvc2l0aW5nL2VtcHR5LXJlbmRlci1zdXJmYWNlLWNyYXNoZXItZXhwZWN0ZWQudHh0
Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT0KLS0tIExheW91dFRlc3RzL3BsYXRmb3JtL2Nocm9taXVtL2NvbXBvc2l0aW5n
L2VtcHR5LXJlbmRlci1zdXJmYWNlLWNyYXNoZXItZXhwZWN0ZWQudHh0CShyZXZpc2lvbiAwKQor
KysgTGF5b3V0VGVzdHMvcGxhdGZvcm0vY2hyb21pdW0vY29tcG9zaXRpbmcvZW1wdHktcmVuZGVy
LXN1cmZhY2UtY3Jhc2hlci1leHBlY3RlZC50eHQJKHJldmlzaW9uIDApCkBAIC0wLDAgKzEsMyBA
QAorVGhpcyBwYWdlIHRlc3RzIHRoYXQgYW4gZW1wdHkgcmVuZGVyIHN1cmZhY2UgZG9lcyBub3Qg
Y3Jhc2ggYXMgcmVwb3J0ZXJkIGluIHRoaXMgYnVnLiBQYXNzIGlmIHRoaXMgZG9lcyBub3QgY3Jh
c2guCisKKwpJbmRleDogTGF5b3V0VGVzdHMvcGxhdGZvcm0vY2hyb21pdW0vY29tcG9zaXRpbmcv
ZW1wdHktcmVuZGVyLXN1cmZhY2UtY3Jhc2hlci5odG1sCj09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIExheW91dFRl
c3RzL3BsYXRmb3JtL2Nocm9taXVtL2NvbXBvc2l0aW5nL2VtcHR5LXJlbmRlci1zdXJmYWNlLWNy
YXNoZXIuaHRtbAkocmV2aXNpb24gMCkKKysrIExheW91dFRlc3RzL3BsYXRmb3JtL2Nocm9taXVt
L2NvbXBvc2l0aW5nL2VtcHR5LXJlbmRlci1zdXJmYWNlLWNyYXNoZXIuaHRtbAkocmV2aXNpb24g
MCkKQEAgLTAsMCArMSwzNCBAQAorPCFET0NUWVBFPgorPGh0bWw+Cis8aGVhZD4KKzx0aXRsZT5F
bXB0eSBSZW5kZXIgU3VyZmFjZTwvdGl0bGU+CisgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyIgbWVk
aWE9InNjcmVlbiI+CisgICAgLmNvbnRhaW5lciB7CisgICAgICBwb3NpdGlvbjogcmVsYXRpdmU7
CisgICAgICBoZWlnaHQ6IDB4OworICAgICAgd2lkdGg6IDBweDsKKyAgICAgIG9wYWNpdHk6MC41
OworICAgIH0KKyAgICAKKyAgICAuY2hpbGQgeworICAgICAgLXdlYmtpdC10cmFuc2Zvcm06IHRy
YW5zbGF0ZVooMCk7CisgICAgICBoZWlnaHQ6IDBweDsKKyAgICAgIHdpZHRoOiAwcHg7CisgICAg
ICBiYWNrZ3JvdW5kLWNvbG9yOiByZWQ7CisgICAgfSAgICAKKyAgPC9zdHlsZT4KKyAgPHNjcmlw
dCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiIGNoYXJzZXQ9InV0Zi04Ij4KKyAgICBpZiAod2luZG93
LmxheW91dFRlc3RDb250cm9sbGVyKQorICAgICAgbGF5b3V0VGVzdENvbnRyb2xsZXIuZHVtcEFz
VGV4dCgpOworICA8L3NjcmlwdD4KKworPC9oZWFkPgorPGJvZHk+Cis8cD5UaGlzIHBhZ2UgdGVz
dHMgdGhhdCBhbiBlbXB0eSByZW5kZXIgc3VyZmFjZSBkb2VzIG5vdCBjcmFzaCBhcyByZXBvcnRl
cmQgaW4gPGEgaHJlZj0naHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTUx
NDMyJz50aGlzIGJ1ZzwvYT4uIFBhc3MgaWYgdGhpcyBkb2VzIG5vdCBjcmFzaC48L3A+CisKKzxk
aXYgY2xhc3M9ImNvbnRhaW5lciI+CisgIDxkaXYgY2xhc3M9ImNoaWxkIj4gPC9kaXY+Cis8L2Rp
dj4KKworPC9ib2R5PgorPC9odG1sPgo=
</data>
<flag name="review"
          id="68234"
          type_id="1"
          status="+"
          setter="kbr"
    />
    <flag name="commit-queue"
          id="68235"
          type_id="3"
          status="-"
          setter="vangelis"
    />
          </attachment>
      

    </bug>

</bugzilla>