Bug 11505

Summary: REGRESSION: Null pointer deref in HitTestResult::spellingToolTip() (assertion failure in Node::document)
Product: WebKit Reporter: mitz
Component: WebCore Misc.Assignee: Nobody <webkit-unassigned>
Status: RESOLVED FIXED    
Severity: Normal CC: ap, sullivan
Priority: P1 Keywords: Regression
Version: 420+   
Hardware: Mac   
OS: OS X 10.4   
Attachments:
Description Flags
manual test case
none
Automatic test
none
Patch with the automated test bdakin: review+

Description mitz 2006-11-03 08:01:06 PST
HitTestResult::spellingToolTip() dereferences m_innerNonSharedNode which may be null. This causes the first assert in Node::document() to fail.
Comment 1 Alexey Proskuryakov 2006-11-04 02:48:44 PST
Created attachment 11377 [details]
manual test case
Comment 2 mitz 2006-11-04 06:29:49 PST
Created attachment 11379 [details]
Automatic test
Comment 3 Beth Dakin 2006-11-06 23:30:01 PST
Fixed with r17640.
Comment 4 mitz 2006-11-07 07:03:51 PST
Created attachment 11414 [details]
Patch with the automated test

Alexey suggested adding this test which is specific to the missing null check. The test that was included with the fix doesn't cover it, since the fix prevents a null m_innerNonSharedNode in that case.
Comment 5 Alexey Proskuryakov 2006-11-07 10:11:25 PST
Reopening for review.
Comment 6 Beth Dakin 2006-11-07 10:31:19 PST
Comment on attachment 11414 [details]
Patch with the automated test

good call!
Comment 7 Alexey Proskuryakov 2006-11-07 10:47:52 PST
Test committed revision 17642.