<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>97988</bug_id>
          
          <creation_ts>2012-09-30 19:02:04 -0700</creation_ts>
          <short_desc>Crash on FrameTree::scopedChildCount()</short_desc>
          <delta_ts>2012-09-30 22:56:39 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>DOM</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Hajime Morrita">morrita</reporter>
          <assigned_to name="Hajime Morrita">morrita</assigned_to>
          <cc>rniwa</cc>
    
    <cc>tkent</cc>
    
    <cc>webkit.review.bot</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>731362</commentid>
    <comment_count>0</comment_count>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2012-09-30 19:02:04 -0700</bug_when>
    <thetext>This upstreams http://code.google.com/p/chromium/issues/detail?id=131646</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>731363</commentid>
    <comment_count>1</comment_count>
      <attachid>166398</attachid>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2012-09-30 19:06:40 -0700</bug_when>
    <thetext>Created attachment 166398
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>731368</commentid>
    <comment_count>2</comment_count>
      <attachid>166398</attachid>
    <who name="Kent Tamura">tkent</who>
    <bug_when>2012-09-30 20:16:41 -0700</bug_when>
    <thetext>Comment on attachment 166398
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=166398&amp;action=review

&gt; Source/WebCore/page/FrameTree.cpp:211
&gt; +    Document* document = m_thisFrame-&gt;document();
&gt; +    if (!document)
&gt; +        return 0;
&gt; +    return scopedChild(index, document);

Can you make scopedChild(unsigned, TreeScope*) and scopedChild(TreeScope*) accept null for TreeScope* ?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>731379</commentid>
    <comment_count>3</comment_count>
      <attachid>166405</attachid>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2012-09-30 21:46:31 -0700</bug_when>
    <thetext>Created attachment 166405
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>731380</commentid>
    <comment_count>4</comment_count>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2012-09-30 21:47:23 -0700</bug_when>
    <thetext>Kent-san, thanks for reviewing!

(In reply to comment #2)
&gt; 
&gt; Can you make scopedChild(unsigned, TreeScope*) and scopedChild(TreeScope*) accept null for TreeScope* ?
Done.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>731382</commentid>
    <comment_count>5</comment_count>
      <attachid>166405</attachid>
    <who name="Kent Tamura">tkent</who>
    <bug_when>2012-09-30 21:57:03 -0700</bug_when>
    <thetext>Comment on attachment 166405
Patch

ok</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>731391</commentid>
    <comment_count>6</comment_count>
      <attachid>166405</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2012-09-30 22:56:36 -0700</bug_when>
    <thetext>Comment on attachment 166405
Patch

Clearing flags on attachment: 166405

Committed r130006: &lt;http://trac.webkit.org/changeset/130006&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>731392</commentid>
    <comment_count>7</comment_count>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2012-09-30 22:56:39 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>166398</attachid>
            <date>2012-09-30 19:06:40 -0700</date>
            <delta_ts>2012-09-30 21:46:28 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-97988-20121001110553.patch</filename>
            <type>text/plain</type>
            <size>2283</size>
            <attacher name="Hajime Morrita">morrita</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTMwMDAwCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggOWY2ZjQ1MjBmNDkzOGE5
MjRkMzVkNWFmOTQ2MWUyZDk4YWRhYWY0Zi4uZWQ1MTY1OGU1OGQ2Y2Y4YWZiMmRkZjk1NGEyNzQx
MTA1NDM0YjBmYSAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDIwIEBACisyMDEyLTA5LTMwICBNT1JJ
VEEgSGFqaW1lICA8bW9ycml0YUBnb29nbGUuY29tPgorCisgICAgICAgIGh0dHBzOi8vYnVncy53
ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD05Nzk4OAorICAgICAgICBDcmFzaCBvbiBGcmFtZVRy
ZWU6OnNjb3BlZENoaWxkQ291bnQoKQorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09Q
UyEpLgorCisgICAgICAgIFRoZSBzZXJpZXMgb2YgY3Jhc2ggcmVwb3J0cyBzYXlzIHRoYXQgdGhl
cmUgYXJlIHNvbWUgbnVsbCBwb2ludGVyCisgICAgICAgIGFjY2VzcyBpbiBzY29wZWRDaGlsZENv
dW50KCkuIFRoaXMgY2hhbmdlIGFkZGVkIGEgbnVsbCBndWFyZAorICAgICAgICBhZ2FpbnN0IEZy
YW1lOjpkb2N1bWVudCgpLCB0aGF0IGNhbiByZXR1cm4gbnVsbC4KKworICAgICAgICBObyBuZXcg
dGVzdHMuIFRoaXMgaXMgdGllZCB0byBzb21lIHNwZWNpZmljIHRpbWluZyBhbmQgaXMgaGFyZCB0
byByZXByb2R1Y2UuCisKKyAgICAgICAgKiBwYWdlL0ZyYW1lVHJlZS5jcHA6CisgICAgICAgIChX
ZWJDb3JlOjpGcmFtZVRyZWU6OnNjb3BlZENoaWxkKToKKyAgICAgICAgKFdlYkNvcmU6OkZyYW1l
VHJlZTo6c2NvcGVkQ2hpbGRDb3VudCk6CisKIDIwMTItMDktMzAgIEFuZHJlYXMgS2xpbmcgIDxr
bGluZ0B3ZWJraXQub3JnPgogCiAgICAgICAgIFNwbGl0IEV2ZW50VGFyZ2V0RGF0YSBvdXQgb2Yg
Tm9kZVJhcmVEYXRhIHRvIHJlZHVjZSBtZW1vcnkgdXNlLgpkaWZmIC0tZ2l0IGEvU291cmNlL1dl
YkNvcmUvcGFnZS9GcmFtZVRyZWUuY3BwIGIvU291cmNlL1dlYkNvcmUvcGFnZS9GcmFtZVRyZWUu
Y3BwCmluZGV4IDZmODE3MTQ1MDE5MjJmYjhhZGQ4ZTc2NGI5NTc4OTk0ZDBkODUwNWMuLjZiYmQ0
NDU2Mzg0MWFmZjEzZTdiYjkwMzNiMjM4NWJlNmI4MWNkNWEgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9X
ZWJDb3JlL3BhZ2UvRnJhbWVUcmVlLmNwcAorKysgYi9Tb3VyY2UvV2ViQ29yZS9wYWdlL0ZyYW1l
VHJlZS5jcHAKQEAgLTIwNSwxOCArMjA1LDI5IEBAIGlubGluZSB1bnNpZ25lZCBGcmFtZVRyZWU6
OnNjb3BlZENoaWxkQ291bnQoVHJlZVNjb3BlKiBzY29wZSkgY29uc3QKIAogRnJhbWUqIEZyYW1l
VHJlZTo6c2NvcGVkQ2hpbGQodW5zaWduZWQgaW5kZXgpIGNvbnN0CiB7Ci0gICAgcmV0dXJuIHNj
b3BlZENoaWxkKGluZGV4LCBtX3RoaXNGcmFtZS0+ZG9jdW1lbnQoKSk7CisgICAgRG9jdW1lbnQq
IGRvY3VtZW50ID0gbV90aGlzRnJhbWUtPmRvY3VtZW50KCk7CisgICAgaWYgKCFkb2N1bWVudCkK
KyAgICAgICAgcmV0dXJuIDA7CisgICAgcmV0dXJuIHNjb3BlZENoaWxkKGluZGV4LCBkb2N1bWVu
dCk7CiB9CiAKIEZyYW1lKiBGcmFtZVRyZWU6OnNjb3BlZENoaWxkKGNvbnN0IEF0b21pY1N0cmlu
ZyYgbmFtZSkgY29uc3QKIHsKLSAgICByZXR1cm4gc2NvcGVkQ2hpbGQobmFtZSwgbV90aGlzRnJh
bWUtPmRvY3VtZW50KCkpOworICAgIERvY3VtZW50KiBkb2N1bWVudCA9IG1fdGhpc0ZyYW1lLT5k
b2N1bWVudCgpOworICAgIGlmICghZG9jdW1lbnQpCisgICAgICAgIHJldHVybiAwOworICAgIHJl
dHVybiBzY29wZWRDaGlsZChuYW1lLCBkb2N1bWVudCk7CiB9CiAKIHVuc2lnbmVkIEZyYW1lVHJl
ZTo6c2NvcGVkQ2hpbGRDb3VudCgpIGNvbnN0CiB7Ci0gICAgaWYgKG1fc2NvcGVkQ2hpbGRDb3Vu
dCA9PSBpbnZhbGlkQ291bnQpCi0gICAgICAgIG1fc2NvcGVkQ2hpbGRDb3VudCA9IHNjb3BlZENo
aWxkQ291bnQobV90aGlzRnJhbWUtPmRvY3VtZW50KCkpOworICAgIGlmIChtX3Njb3BlZENoaWxk
Q291bnQgPT0gaW52YWxpZENvdW50KSB7CisgICAgICAgIERvY3VtZW50KiBkb2N1bWVudCA9IG1f
dGhpc0ZyYW1lLT5kb2N1bWVudCgpOworICAgICAgICBpZiAoIWRvY3VtZW50KQorICAgICAgICAg
ICAgcmV0dXJuIDA7CisgICAgICAgIG1fc2NvcGVkQ2hpbGRDb3VudCA9IHNjb3BlZENoaWxkQ291
bnQoZG9jdW1lbnQpOworICAgIH0KKwogICAgIHJldHVybiBtX3Njb3BlZENoaWxkQ291bnQ7CiB9
CiAK
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>166405</attachid>
            <date>2012-09-30 21:46:31 -0700</date>
            <delta_ts>2012-09-30 22:56:35 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-97988-20121001134545.patch</filename>
            <type>text/plain</type>
            <size>2450</size>
            <attacher name="Hajime Morrita">morrita</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTMwMDAwCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggOWY2ZjQ1MjBmNDkzOGE5
MjRkMzVkNWFmOTQ2MWUyZDk4YWRhYWY0Zi4uYzg0ZjkyOTg0MTMwNjI1OTk0NjRhNWM3NTk1N2I0
OTFmMjJiMjQ1YyAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDIxIEBACisyMDEyLTA5LTMwICBNT1JJ
VEEgSGFqaW1lICA8bW9ycml0YUBnb29nbGUuY29tPgorCisgICAgICAgIGh0dHBzOi8vYnVncy53
ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD05Nzk4OAorICAgICAgICBDcmFzaCBvbiBGcmFtZVRy
ZWU6OnNjb3BlZENoaWxkQ291bnQoKQorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09Q
UyEpLgorCisgICAgICAgIFRoZSBzZXJpZXMgb2YgY3Jhc2ggcmVwb3J0cyBzYXlzIHRoYXQgdGhl
cmUgYXJlIHNvbWUgbnVsbCBwb2ludGVyCisgICAgICAgIGFjY2VzcyBpbiBzY29wZWRDaGlsZENv
dW50KCkuIFRoaXMgY2hhbmdlIGFkZGVkIGEgbnVsbCBndWFyZAorICAgICAgICBhZ2FpbnN0IEZy
YW1lOjpkb2N1bWVudCgpLCB0aGF0IGNhbiByZXR1cm4gbnVsbC4KKworICAgICAgICBObyBuZXcg
dGVzdHMuIFRoaXMgaXMgdGllZCB0byBzb21lIHNwZWNpZmljIHRpbWluZyBhbmQgaXMgaGFyZCB0
byByZXByb2R1Y2UuCisKKyAgICAgICAgKiBwYWdlL0ZyYW1lVHJlZS5jcHA6CisgICAgICAgIChX
ZWJDb3JlOjpGcmFtZVRyZWU6OnNjb3BlZENoaWxkQ291bnQpOgorICAgICAgICAoV2ViQ29yZTo6
RnJhbWVUcmVlOjpzY29wZWRDaGlsZCk6CisgICAgICAgIChXZWJDb3JlKToKKwogMjAxMi0wOS0z
MCAgQW5kcmVhcyBLbGluZyAgPGtsaW5nQHdlYmtpdC5vcmc+CiAKICAgICAgICAgU3BsaXQgRXZl
bnRUYXJnZXREYXRhIG91dCBvZiBOb2RlUmFyZURhdGEgdG8gcmVkdWNlIG1lbW9yeSB1c2UuCmRp
ZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9wYWdlL0ZyYW1lVHJlZS5jcHAgYi9Tb3VyY2UvV2Vi
Q29yZS9wYWdlL0ZyYW1lVHJlZS5jcHAKaW5kZXggNmY4MTcxNDUwMTkyMmZiOGFkZDhlNzY0Yjk1
Nzg5OTRkMGQ4NTA1Yy4uMWUwYWZlMWRkYzdkODU0MTE3ZmFkODdkYmVjYzA5OWFkNGZlNjVlNCAx
MDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvcGFnZS9GcmFtZVRyZWUuY3BwCisrKyBiL1NvdXJj
ZS9XZWJDb3JlL3BhZ2UvRnJhbWVUcmVlLmNwcApAQCAtMTcyLDYgKzE3Miw5IEBAIEF0b21pY1N0
cmluZyBGcmFtZVRyZWU6OnVuaXF1ZUNoaWxkTmFtZShjb25zdCBBdG9taWNTdHJpbmcmIHJlcXVl
c3RlZE5hbWUpIGNvbnN0CiAKIGlubGluZSBGcmFtZSogRnJhbWVUcmVlOjpzY29wZWRDaGlsZCh1
bnNpZ25lZCBpbmRleCwgVHJlZVNjb3BlKiBzY29wZSkgY29uc3QKIHsKKyAgICBpZiAoIXNjb3Bl
KQorICAgICAgICByZXR1cm4gMDsKKwogICAgIHVuc2lnbmVkIHNjb3BlZEluZGV4ID0gMDsKICAg
ICBmb3IgKEZyYW1lKiByZXN1bHQgPSBmaXJzdENoaWxkKCk7IHJlc3VsdDsgcmVzdWx0ID0gcmVz
dWx0LT50cmVlKCktPm5leHRTaWJsaW5nKCkpIHsKICAgICAgICAgaWYgKHJlc3VsdC0+aW5TY29w
ZShzY29wZSkpIHsKQEAgLTE4Niw2ICsxODksOSBAQCBpbmxpbmUgRnJhbWUqIEZyYW1lVHJlZTo6
c2NvcGVkQ2hpbGQodW5zaWduZWQgaW5kZXgsIFRyZWVTY29wZSogc2NvcGUpIGNvbnN0CiAKIGlu
bGluZSBGcmFtZSogRnJhbWVUcmVlOjpzY29wZWRDaGlsZChjb25zdCBBdG9taWNTdHJpbmcmIG5h
bWUsIFRyZWVTY29wZSogc2NvcGUpIGNvbnN0CiB7CisgICAgaWYgKCFzY29wZSkKKyAgICAgICAg
cmV0dXJuIDA7CisKICAgICBmb3IgKEZyYW1lKiBjaGlsZCA9IGZpcnN0Q2hpbGQoKTsgY2hpbGQ7
IGNoaWxkID0gY2hpbGQtPnRyZWUoKS0+bmV4dFNpYmxpbmcoKSkKICAgICAgICAgaWYgKGNoaWxk
LT50cmVlKCktPnVuaXF1ZU5hbWUoKSA9PSBuYW1lICYmIGNoaWxkLT5pblNjb3BlKHNjb3BlKSkK
ICAgICAgICAgICAgIHJldHVybiBjaGlsZDsKQEAgLTE5NCw2ICsyMDAsOSBAQCBpbmxpbmUgRnJh
bWUqIEZyYW1lVHJlZTo6c2NvcGVkQ2hpbGQoY29uc3QgQXRvbWljU3RyaW5nJiBuYW1lLCBUcmVl
U2NvcGUqIHNjb3BlKQogCiBpbmxpbmUgdW5zaWduZWQgRnJhbWVUcmVlOjpzY29wZWRDaGlsZENv
dW50KFRyZWVTY29wZSogc2NvcGUpIGNvbnN0CiB7CisgICAgaWYgKCFzY29wZSkKKyAgICAgICAg
cmV0dXJuIDA7CisKICAgICB1bnNpZ25lZCBzY29wZWRDb3VudCA9IDA7CiAgICAgZm9yIChGcmFt
ZSogcmVzdWx0ID0gZmlyc3RDaGlsZCgpOyByZXN1bHQ7IHJlc3VsdCA9IHJlc3VsdC0+dHJlZSgp
LT5uZXh0U2libGluZygpKSB7CiAgICAgICAgIGlmIChyZXN1bHQtPmluU2NvcGUoc2NvcGUpKQo=
</data>

          </attachment>
      

    </bug>

</bugzilla>