<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>57405</bug_id>
          
          <creation_ts>2011-03-29 17:22:50 -0700</creation_ts>
          <short_desc>CrashTracer: 301 crashes in Safari at com.apple.WebCore: WebCore::AccessibilityRenderObject::visiblePositionForPoint const + 297</short_desc>
          <delta_ts>2011-04-20 17:54:47 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Accessibility</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>PC</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="chris fleizach">cfleizach</reporter>
          <assigned_to name="chris fleizach">cfleizach</assigned_to>
          <cc>bdakin</cc>
    
    <cc>commit-queue</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>375918</commentid>
    <comment_count>0</comment_count>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2011-03-29 17:22:50 -0700</bug_when>
    <thetext>Thread 0 Crashed ↩:  Dispatch queue: com.apple.main-thread
0   com.apple.WebCore             	0x7fff869fb329 WebCore::AccessibilityRenderObject::visiblePositionForPoint(WebCore::IntPoint const&amp;) const + 297 (/SourceCache/WebCore/
Exception Type:  EXC_BAD_ACCESS (SIGSEGV)
Exception Codes: KERN_INVALID_ADDRESS at 0x0000000000000038
Crashed Thread:  0  Dispatch queue: com.apple.main-thread

WebCore-7533.20.24/accessibility/AccessibilityRenderObject.cpp:2557)
1   com.apple.WebCore             	0x7fff86719c22 -[AccessibilityObjectWrapper accessibilityAttributeValue:forParameter:] + 2562 (/SourceCache/WebCore/WebCore-7533.20.24/accessibility/mac/AccessibilityObjectWrapper.mm:2360)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>375920</commentid>
    <comment_count>1</comment_count>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2011-03-29 17:23:11 -0700</bug_when>
    <thetext>That line is

FrameView* frameView = m_renderer-&gt;document()-&gt;topDocument()-&gt;renderer()-&gt;view()-&gt;frameView();

which seems likely that there was a nil pointer in there somewhere</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>375921</commentid>
    <comment_count>2</comment_count>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2011-03-29 17:23:49 -0700</bug_when>
    <thetext>unfortunately, i can&apos;t reproduce this crash, and don&apos;t know how it occurs</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>376350</commentid>
    <comment_count>3</comment_count>
      <attachid>87541</attachid>
    <who name="chris fleizach">cfleizach</who>
    <bug_when>2011-03-30 08:35:34 -0700</bug_when>
    <thetext>Created attachment 87541
patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>389704</commentid>
    <comment_count>4</comment_count>
      <attachid>87541</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2011-04-20 17:54:42 -0700</bug_when>
    <thetext>Comment on attachment 87541
patch

Clearing flags on attachment: 87541

Committed r84444: &lt;http://trac.webkit.org/changeset/84444&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>389705</commentid>
    <comment_count>5</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2011-04-20 17:54:47 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>87541</attachid>
            <date>2011-03-30 08:35:34 -0700</date>
            <delta_ts>2011-04-20 17:54:42 -0700</delta_ts>
            <desc>patch</desc>
            <filename>patch.txt</filename>
            <type>text/plain</type>
            <size>3699</size>
            <attacher name="chris fleizach">cfleizach</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJDb3JlL0NoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2Vi
Q29yZS9DaGFuZ2VMb2cJKHJldmlzaW9uIDgyNDQ4KQorKysgU291cmNlL1dlYkNvcmUvQ2hhbmdl
TG9nCSh3b3JraW5nIGNvcHkpCkBAIC0xLDMgKzEsMjIgQEAKKzIwMTEtMDMtMzAgIENocmlzIEZs
ZWl6YWNoICA8Y2ZsZWl6YWNoQGFwcGxlLmNvbT4KKworICAgICAgICBSZXZpZXdlZCBieSBOT0JP
RFkgKE9PUFMhKS4KKworICAgICAgICBDcmFzaFRyYWNlcjogMzAxIGNyYXNoZXMgaW4gU2FmYXJp
IGF0IGNvbS5hcHBsZS5XZWJDb3JlOiBXZWJDb3JlOjpBY2Nlc3NpYmlsaXR5UmVuZGVyT2JqZWN0
Ojp2aXNpYmxlUG9zaXRpb25Gb3JQb2ludCBjb25zdCArIDI5NworICAgICAgICBodHRwczovL2J1
Z3Mud2Via2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9NTc0MDUKKworICAgICAgICBUaGUgb2ZmZW5k
aW5nIGxpbmUgaW4gdGhpcyBjcmFzaCB3YXMgYSBudWxsIHBvaW50ZXIgYWNjZXNzIGluCisgICAg
ICAgICAgIG1fcmVuZGVyZXItPmRvY3VtZW50KCktPnRvcERvY3VtZW50KCktPnJlbmRlcmVyKCkt
PnZpZXcoKS0+ZnJhbWVWaWV3KCk7CisgICAgICAgIEl0IHNlZW1zIGxpa2VseSB0aGF0IG9uZSBv
ZiB0aG9zZSBjYWxscyB3YXMgaW52YWxpZC4gSSBjb3VsZCBub3QgcmVwcm9kdWNlIGFuZCB0aGVy
ZSB3YXMgbm8KKyAgICAgICAgaW5mb3JtYXRpb24gb24gcmVwcm9kdWNpYmxlIHN0ZXBzLCBoZW5j
ZSB0aGUgYWJzZW5jZSBvZiBhIGxheW91dCB0ZXN0LgorCisgICAgICAgICogYWNjZXNzaWJpbGl0
eS9BY2Nlc3NpYmlsaXR5UmVuZGVyT2JqZWN0LmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OkFjY2Vz
c2liaWxpdHlSZW5kZXJPYmplY3Q6OnRvcFJlbmRlcmVyKToKKyAgICAgICAgKFdlYkNvcmU6OkFj
Y2Vzc2liaWxpdHlSZW5kZXJPYmplY3Q6OnRvcERvY3VtZW50KToKKyAgICAgICAgKFdlYkNvcmU6
OkFjY2Vzc2liaWxpdHlSZW5kZXJPYmplY3Q6OnRvcERvY3VtZW50RnJhbWVWaWV3KToKKyAgICAg
ICAgKFdlYkNvcmU6OkFjY2Vzc2liaWxpdHlSZW5kZXJPYmplY3Q6OnZpc2libGVQb3NpdGlvbkZv
clBvaW50KToKKyAgICAgICAgKiBhY2Nlc3NpYmlsaXR5L0FjY2Vzc2liaWxpdHlSZW5kZXJPYmpl
Y3QuaDoKKwogMjAxMS0wMy0zMCAgTGV2aSBXZWludHJhdWIgIDxsZXZpd0BjaHJvbWl1bS5vcmc+
CiAKICAgICAgICAgUmV2aWV3ZWQgYnkgUnlvc3VrZSBOaXdhLgpJbmRleDogU291cmNlL1dlYkNv
cmUvYWNjZXNzaWJpbGl0eS9BY2Nlc3NpYmlsaXR5UmVuZGVyT2JqZWN0LmgKPT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQot
LS0gU291cmNlL1dlYkNvcmUvYWNjZXNzaWJpbGl0eS9BY2Nlc3NpYmlsaXR5UmVuZGVyT2JqZWN0
LmgJKHJldmlzaW9uIDgyMzI4KQorKysgU291cmNlL1dlYkNvcmUvYWNjZXNzaWJpbGl0eS9BY2Nl
c3NpYmlsaXR5UmVuZGVyT2JqZWN0LmgJKHdvcmtpbmcgY29weSkKQEAgLTE2OSw2ICsxNjksNyBA
QAogICAgIFJlbmRlclRleHRDb250cm9sKiB0ZXh0Q29udHJvbCgpIGNvbnN0OwogICAgIERvY3Vt
ZW50KiBkb2N1bWVudCgpIGNvbnN0OwogICAgIEZyYW1lVmlldyogdG9wRG9jdW1lbnRGcmFtZVZp
ZXcoKSBjb25zdDsgIAorICAgIERvY3VtZW50KiB0b3BEb2N1bWVudCgpIGNvbnN0OwogICAgIEhU
TUxMYWJlbEVsZW1lbnQqIGxhYmVsRWxlbWVudENvbnRhaW5lcigpIGNvbnN0OwogICAgIAogICAg
IHZpcnR1YWwgS1VSTCB1cmwoKSBjb25zdDsKSW5kZXg6IFNvdXJjZS9XZWJDb3JlL2FjY2Vzc2li
aWxpdHkvQWNjZXNzaWJpbGl0eVJlbmRlck9iamVjdC5jcHAKPT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291cmNl
L1dlYkNvcmUvYWNjZXNzaWJpbGl0eS9BY2Nlc3NpYmlsaXR5UmVuZGVyT2JqZWN0LmNwcAkocmV2
aXNpb24gODIzMjgpCisrKyBTb3VyY2UvV2ViQ29yZS9hY2Nlc3NpYmlsaXR5L0FjY2Vzc2liaWxp
dHlSZW5kZXJPYmplY3QuY3BwCSh3b3JraW5nIGNvcHkpCkBAIC0yMzA3LDcgKzIzMDcsMTEgQEAK
IAogUmVuZGVyVmlldyogQWNjZXNzaWJpbGl0eVJlbmRlck9iamVjdDo6dG9wUmVuZGVyZXIoKSBj
b25zdAogewotICAgIHJldHVybiBtX3JlbmRlcmVyLT5kb2N1bWVudCgpLT50b3BEb2N1bWVudCgp
LT5yZW5kZXJWaWV3KCk7CisgICAgRG9jdW1lbnQqIHRvcERvYyA9IHRvcERvY3VtZW50KCk7Cisg
ICAgaWYgKCF0b3BEb2MpCisgICAgICAgIHJldHVybiAwOworICAgIAorICAgIHJldHVybiB0b3BE
b2MtPnJlbmRlclZpZXcoKTsKIH0KIAogRG9jdW1lbnQqIEFjY2Vzc2liaWxpdHlSZW5kZXJPYmpl
Y3Q6OmRvY3VtZW50KCkgY29uc3QKQEAgLTIzMTcsOSArMjMyMSwxOSBAQAogICAgIHJldHVybiBt
X3JlbmRlcmVyLT5kb2N1bWVudCgpOwogfQogCitEb2N1bWVudCogQWNjZXNzaWJpbGl0eVJlbmRl
ck9iamVjdDo6dG9wRG9jdW1lbnQoKSBjb25zdAoreworICAgIGlmICghZG9jdW1lbnQoKSkKKyAg
ICAgICAgcmV0dXJuIDA7CisgICAgcmV0dXJuIGRvY3VtZW50KCktPnRvcERvY3VtZW50KCk7Cit9
CisgICAgCiBGcmFtZVZpZXcqIEFjY2Vzc2liaWxpdHlSZW5kZXJPYmplY3Q6OnRvcERvY3VtZW50
RnJhbWVWaWV3KCkgY29uc3QKIHsKLSAgICByZXR1cm4gdG9wUmVuZGVyZXIoKS0+dmlldygpLT5m
cmFtZVZpZXcoKTsKKyAgICBSZW5kZXJWaWV3KiByZW5kZXJWaWV3ID0gdG9wUmVuZGVyZXIoKTsK
KyAgICBpZiAoIXJlbmRlclZpZXcgfHwgIXJlbmRlclZpZXctPnZpZXcoKSkKKyAgICAgICAgcmV0
dXJuIDA7CisgICAgcmV0dXJuIHJlbmRlclZpZXctPnZpZXcoKS0+ZnJhbWVWaWV3KCk7CiB9CiAK
IFdpZGdldCogQWNjZXNzaWJpbGl0eVJlbmRlck9iamVjdDo6d2lkZ2V0KCkgY29uc3QKQEAgLTI1
NjAsOCArMjU3NCwxOCBAQAogICAgICAgICByZXR1cm4gVmlzaWJsZVBvc2l0aW9uKCk7CiAgICAg
CiAgICAgLy8gY29udmVydCBhYnNvbHV0ZSBwb2ludCB0byB2aWV3IGNvb3JkaW5hdGVzCi0gICAg
RnJhbWVWaWV3KiBmcmFtZVZpZXcgPSBtX3JlbmRlcmVyLT5kb2N1bWVudCgpLT50b3BEb2N1bWVu
dCgpLT5yZW5kZXJlcigpLT52aWV3KCktPmZyYW1lVmlldygpOworICAgIERvY3VtZW50KiB0b3BE
b2MgPSB0b3BEb2N1bWVudCgpOworICAgIGlmICghdG9wRG9jIHx8ICF0b3BEb2MtPnJlbmRlcmVy
KCkgfHwgIXRvcERvYy0+cmVuZGVyZXIoKS0+dmlldygpKQorICAgICAgICByZXR1cm4gVmlzaWJs
ZVBvc2l0aW9uKCk7CisgICAgCisgICAgRnJhbWVWaWV3KiBmcmFtZVZpZXcgPSB0b3BEb2MtPnJl
bmRlcmVyKCktPnZpZXcoKS0+ZnJhbWVWaWV3KCk7CisgICAgaWYgKCFmcmFtZVZpZXcpCisgICAg
ICAgIHJldHVybiBWaXNpYmxlUG9zaXRpb24oKTsKKyAgICAKICAgICBSZW5kZXJWaWV3KiByZW5k
ZXJWaWV3ID0gdG9wUmVuZGVyZXIoKTsKKyAgICBpZiAoIXJlbmRlclZpZXcpCisgICAgICAgIHJl
dHVybiBWaXNpYmxlUG9zaXRpb24oKTsKKyAgICAKICAgICBOb2RlKiBpbm5lck5vZGUgPSAwOwog
ICAgIAogICAgIC8vIGxvY2F0ZSB0aGUgbm9kZSBjb250YWluaW5nIHRoZSBwb2ludAoK
</data>

          </attachment>
      

    </bug>

</bugzilla>