<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>61511</bug_id>
          
          <creation_ts>2011-05-26 01:09:11 -0700</creation_ts>
          <short_desc>WebCore::HTMLSummaryElement::isMainSummary ReadAV@NULL</short_desc>
          <delta_ts>2011-05-27 11:18:21 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>DOM</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>PC</rep_platform>
          <op_sys>Windows Vista</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P1</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Berend-Jan Wever">skylined</reporter>
          <assigned_to name="Hajime Morrita">morrita</assigned_to>
          <cc>ademar</cc>
    
    <cc>dglazkov</cc>
    
    <cc>eric</cc>
    
    <cc>morrita</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>410280</commentid>
    <comment_count>0</comment_count>
    <who name="Berend-Jan Wever">skylined</who>
    <bug_when>2011-05-26 01:09:11 -0700</bug_when>
    <thetext>Chromium: https://code.google.com/p/chromium/issues/detail?id=84018

Repro:
&lt;body onload=&quot;f()&quot;&gt;&lt;/body&gt;
&lt;script&gt;
  function f() {
    var oImg = new Image();
    document.open();
    oImg.innerHTML = &quot;&lt;summary&gt;&quot;;
    document.insertBefore(oImg.lastChild, null);
  }
&lt;/script&gt;

id:             chrome.dll!WebCore::HTMLSummaryElement::isMainSummary ReadAV@NULL (2d237efc21d08331051148bfdb203706)
description:    Attempt to read from unallocated NULL pointer+0x8 in chrome.dll!WebCore::HTMLSummaryElement::isMainSummary
application:    Chromium 13.0.777.0
stack:          chrome.dll!WebCore::HTMLSummaryElement::isMainSummary
                chrome.dll!WebCore::DetailsMarkerControl::rendererIsNeeded
                chrome.dll!WebCore::NodeRendererFactory::createRendererAndStyle
                chrome.dll!WebCore::NodeRendererFactory::createRendererIfNeeded
                chrome.dll!WebCore::Node::createRendererIfNeeded
                chrome.dll!WebCore::Element::attach
                chrome.dll!WebCore::ContainerNode::attach
                chrome.dll!WebCore::ShadowRoot::attach
                chrome.dll!WebCore::Element::attach
                chrome.dll!WebCore::Element::recalcStyle
                chrome.dll!WebCore::Document::recalcStyle
                chrome.dll!WebCore::Document::updateStyleIfNeeded
                chrome.dll!WebCore::Document::implicitClose
                chrome.dll!WebCore::FrameLoader::checkCompleted
                chrome.dll!WebCore::FrameLoader::finishedParsing
                chrome.dll!WebCore::Document::finishedParsing
                chrome.dll!WebCore::HTMLDocumentParser::prepareToStopParsing
                chrome.dll!WebCore::DocumentWriter::endIfNotLoadingMainResource
                chrome.dll!WebCore::FrameLoader::finishedLoading
                chrome.dll!WebCore::MainResourceLoader::didFinishLoading
                chrome.dll!WebCore::ResourceLoader::didFinishLoading
                chrome.dll!WebCore::ResourceHandleInternal::didFinishLoading
                chrome.dll!webkit_glue::WebURLLoaderImpl::Context::OnCompletedRequest
                chrome.dll!ResourceDispatcher::OnRequestComplete
                chrome.dll!IPC::MessageWithTuple&lt;...&gt;::Dispatch&lt;ResourceDispatcher,ResourceDispatcher,void
                chrome.dll!ResourceDispatcher::DispatchMessageW
                chrome.dll!ResourceDispatcher::OnMessageReceived
                chrome.dll!ChildThread::OnMessageReceived
                chrome.dll!RunnableMethod&lt;DetectTabLanguageFunction,void
                chrome.dll!`anonymous namespace&apos;::TaskClosureAdapter::Run
                ...</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>411153</commentid>
    <comment_count>1</comment_count>
      <attachid>95114</attachid>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2011-05-26 22:21:38 -0700</bug_when>
    <thetext>Created attachment 95114
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>411224</commentid>
    <comment_count>2</comment_count>
      <attachid>95114</attachid>
    <who name="Kent Tamura">tkent</who>
    <bug_when>2011-05-27 00:02:18 -0700</bug_when>
    <thetext>Comment on attachment 95114
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=95114&amp;action=review

&gt; LayoutTests/ChangeLog:5
&gt; +        WebCore::HTMLSummaryElement::isMainSummary ReadAV@NULL

nit: ReadAV@NULL is not normal English.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>411230</commentid>
    <comment_count>3</comment_count>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2011-05-27 00:27:09 -0700</bug_when>
    <thetext>Committed r87480: &lt;http://trac.webkit.org/changeset/87480&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>411566</commentid>
    <comment_count>4</comment_count>
    <who name="Ademar Reis">ademar</who>
    <bug_when>2011-05-27 11:18:21 -0700</bug_when>
    <thetext>Revision r87480 cherry-picked into qtwebkit-2.2 with commit 27ca4d8 &lt;http://gitorious.org/webkit/qtwebkit/commit/27ca4d8&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>95114</attachid>
            <date>2011-05-26 22:21:38 -0700</date>
            <delta_ts>2011-05-27 00:02:18 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-61511-20110527142136.patch</filename>
            <type>text/plain</type>
            <size>3405</size>
            <attacher name="Hajime Morrita">morrita</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogODc0NjAKZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL0NoYW5n
ZUxvZyBiL0xheW91dFRlc3RzL0NoYW5nZUxvZwppbmRleCBjNGI1Y2ViYTQwMDM4NTQxMWRiYWI3
NTVhNjZkZGI1OTE2M2FjZmQ0Li5lOTExY2Q3YTUwZjViNDZiYTI1NmJhYzNhNzg5ZjgzNzNlMjg5
ZWQ1IDEwMDY0NAotLS0gYS9MYXlvdXRUZXN0cy9DaGFuZ2VMb2cKKysrIGIvTGF5b3V0VGVzdHMv
Q2hhbmdlTG9nCkBAIC0xLDMgKzEsMTMgQEAKKzIwMTEtMDUtMjYgIE1PUklUQSBIYWppbWUgPG1v
cnJpdGFAZ29vZ2xlLmNvbT4KKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4K
KworICAgICAgICBXZWJDb3JlOjpIVE1MU3VtbWFyeUVsZW1lbnQ6OmlzTWFpblN1bW1hcnkgUmVh
ZEFWQE5VTEwKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lk
PTYxNTExCisKKyAgICAgICAgKiBmYXN0L2h0bWwvZGV0YWlscy1zdW1tYXJ5LWRvY3VtZW50LWNo
aWxkLWV4cGVjdGVkLnR4dDogQWRkZWQuCisgICAgICAgICogZmFzdC9odG1sL2RldGFpbHMtc3Vt
bWFyeS1kb2N1bWVudC1jaGlsZC5odG1sOiBBZGRlZC4KKwogMjAxMS0wNS0yNiAgTU9SSVRBIEhh
amltZSAgPG1vcnJpdGFAZ29vZ2xlLmNvbT4KIAogICAgICAgICBVbnJldmlld2VkIGV4cGVjdGF0
aW9ucyB1cGRhdGUgZm9yIDxkZXRhaWxzPi4KZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL2Zhc3Qv
aHRtbC9kZXRhaWxzLXN1bW1hcnktZG9jdW1lbnQtY2hpbGQtZXhwZWN0ZWQudHh0IGIvTGF5b3V0
VGVzdHMvZmFzdC9odG1sL2RldGFpbHMtc3VtbWFyeS1kb2N1bWVudC1jaGlsZC1leHBlY3RlZC50
eHQKbmV3IGZpbGUgbW9kZSAxMDA2NDQKaW5kZXggMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw
MDAwMDAwMDAwMDAwMC4uMzRlMWZjNWFiZGQwNmNiNTIzZTEyN2I0YWU4OTRmMmJkZWZlZWNlNAot
LS0gL2Rldi9udWxsCisrKyBiL0xheW91dFRlc3RzL2Zhc3QvaHRtbC9kZXRhaWxzLXN1bW1hcnkt
ZG9jdW1lbnQtY2hpbGQtZXhwZWN0ZWQudHh0CkBAIC0wLDAgKzEsMiBAQAorQ09OU09MRSBNRVNT
QUdFOiBsaW5lIDEyOiBQQVNTIHVubGVzcyBjcmFzaAorCmRpZmYgLS1naXQgYS9MYXlvdXRUZXN0
cy9mYXN0L2h0bWwvZGV0YWlscy1zdW1tYXJ5LWRvY3VtZW50LWNoaWxkLmh0bWwgYi9MYXlvdXRU
ZXN0cy9mYXN0L2h0bWwvZGV0YWlscy1zdW1tYXJ5LWRvY3VtZW50LWNoaWxkLmh0bWwKbmV3IGZp
bGUgbW9kZSAxMDA2NDQKaW5kZXggMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw
MDAwMC4uNzdkYmU3NDRkNWY4YjIwYTdkMTUxM2FjYTFkMjU3NWI2NTkyMjdmZAotLS0gL2Rldi9u
dWxsCisrKyBiL0xheW91dFRlc3RzL2Zhc3QvaHRtbC9kZXRhaWxzLXN1bW1hcnktZG9jdW1lbnQt
Y2hpbGQuaHRtbApAQCAtMCwwICsxLDE2IEBACis8aHRtbD4KKzxib2R5IG9ubG9hZD0idGVzdCgp
Ij4KKzxzY3JpcHQ+CitpZiAod2luZG93LmxheW91dFRlc3RDb250cm9sbGVyKQorICAgIGxheW91
dFRlc3RDb250cm9sbGVyLmR1bXBBc1RleHQoKTsKKworZnVuY3Rpb24gdGVzdCgpIHsKKyAgICBk
b2N1bWVudC5vcGVuKCk7CisgICAgZG9jdW1lbnQuaW5zZXJ0QmVmb3JlKGRvY3VtZW50LmNyZWF0
ZUVsZW1lbnQoInN1bW1hcnkiKSk7CisgICAgLy8gVGhlIGRvY3VtZW50IGRvbid0IGhhdmUgPGJv
ZHk+IHNvIHdlIG5lZWQgdXNlIGNvbnNvbGUubG9nKCkKKyAgICAvLyB0byBtYWtlIHJlYWRhYmxl
IGV4cGVjdGF0aW9uLgorICAgIGNvbnNvbGUubG9nKCJQQVNTIHVubGVzcyBjcmFzaCIpOworfQor
PC9zY3JpcHQ+Cis8L2JvZHk+Cis8L2h0bWw+CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggZjIzMjAwMjFiYmViNTI2
OWEwYWQ5Y2U4ZTZkODRjMWRhZjViNmFjYi4uNTU4YTczNzY0ODBiYzVmMjIyN2U2NzhjNmFhN2M1
NDlhMDc1MWJkNCAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDE3IEBACisyMDExLTA1LTI2ICBNT1JJ
VEEgSGFqaW1lICA8bW9ycml0YUBnb29nbGUuY29tPgorCisgICAgICAgIFJldmlld2VkIGJ5IE5P
Qk9EWSAoT09QUyEpLgorCisgICAgICAgIFdlYkNvcmU6OkhUTUxTdW1tYXJ5RWxlbWVudDo6aXNN
YWluU3VtbWFyeSBSZWFkQVZATlVMTAorICAgICAgICBodHRwczovL2J1Z3Mud2Via2l0Lm9yZy9z
aG93X2J1Zy5jZ2k/aWQ9NjE1MTEKKworICAgICAgICBSZW1vdmVkIFVubmVjZXNzYXJ5IHdyb25n
IGNhc3QgdG8gRWxtZW1lbnQsIHdoaWNoIGNhbiBiZSBub24tRWxlbWVudC4KKworICAgICAgICBU
ZXN0OiBmYXN0L2h0bWwvZGV0YWlscy1zdW1tYXJ5LWRvY3VtZW50LWNoaWxkLmh0bWwKKworICAg
ICAgICAqIGh0bWwvSFRNTFN1bW1hcnlFbGVtZW50LmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OkhU
TUxTdW1tYXJ5RWxlbWVudDo6ZGV0YWlsc0VsZW1lbnQpOgorCiAyMDExLTA1LTI2ICBTdGVwaGFu
aWUgTGV3aXMgIDxzbGV3aXNAYXBwbGUuY29tPgogCiAgICAgICAgIFJldmlld2VkIGJ5IEdlb2Zm
IEdhcmVuLgpkaWZmIC0tZ2l0IGEvU291cmNlL1dlYkNvcmUvaHRtbC9IVE1MU3VtbWFyeUVsZW1l
bnQuY3BwIGIvU291cmNlL1dlYkNvcmUvaHRtbC9IVE1MU3VtbWFyeUVsZW1lbnQuY3BwCmluZGV4
IDAyYzQ0M2I0MGFiMzJiODEzMGRlNzFmMmVkNjYxYjA1ZTc5MTY3MWYuLmQ1MjQ3NTcyNTM3ZjVh
YzkxMDQ4OWQ5NDNmM2I0OGU5ZjkzZTk1NDcgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJDb3JlL2h0
bWwvSFRNTFN1bW1hcnlFbGVtZW50LmNwcAorKysgYi9Tb3VyY2UvV2ViQ29yZS9odG1sL0hUTUxT
dW1tYXJ5RWxlbWVudC5jcHAKQEAgLTgyLDcgKzgyLDcgQEAgdm9pZCBIVE1MU3VtbWFyeUVsZW1l
bnQ6OmNyZWF0ZVNoYWRvd1N1YnRyZWUoKQogCiBIVE1MRGV0YWlsc0VsZW1lbnQqIEhUTUxTdW1t
YXJ5RWxlbWVudDo6ZGV0YWlsc0VsZW1lbnQoKSBjb25zdAogewotICAgIEVsZW1lbnQqIG1heURl
dGFpbHMgPSB0b0VsZW1lbnQoY29uc3RfY2FzdDxIVE1MU3VtbWFyeUVsZW1lbnQqPih0aGlzKS0+
cGFyZW50Tm9kZUZvclJlbmRlcmluZ0FuZFN0eWxlKCkpOworICAgIE5vZGUqIG1heURldGFpbHMg
PSBjb25zdF9jYXN0PEhUTUxTdW1tYXJ5RWxlbWVudCo+KHRoaXMpLT5wYXJlbnROb2RlRm9yUmVu
ZGVyaW5nQW5kU3R5bGUoKTsKICAgICBpZiAoIW1heURldGFpbHMgfHwgIW1heURldGFpbHMtPmhh
c1RhZ05hbWUoZGV0YWlsc1RhZykpCiAgICAgICAgIHJldHVybiAwOwogICAgIHJldHVybiBzdGF0
aWNfY2FzdDxIVE1MRGV0YWlsc0VsZW1lbnQqPihtYXlEZXRhaWxzKTsK
</data>
<flag name="review"
          id="88548"
          type_id="1"
          status="+"
          setter="tkent"
    />
          </attachment>
      

    </bug>

</bugzilla>