Summary: | Remove simpleUserAgentStyleSheet (to fix flaky fast/lists/001.html and fast/lists/001-vertical.html) | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Truitt Savell <tsavell> | ||||||||||||
Component: | CSS | Assignee: | Antoine Quint <graouts> | ||||||||||||
Status: | RESOLVED FIXED | ||||||||||||||
Severity: | Normal | CC: | changseok, esprehn+autocc, ews-watchlist, glenn, graouts, graouts, koivisto, kondapallykalyan, pdr, webkit-bot-watchers-bugzilla, webkit-bug-importer | ||||||||||||
Priority: | P2 | Keywords: | InRadar | ||||||||||||
Version: | WebKit Nightly Build | ||||||||||||||
Hardware: | Unspecified | ||||||||||||||
OS: | Unspecified | ||||||||||||||
See Also: | https://bugs.webkit.org/show_bug.cgi?id=218894 | ||||||||||||||
Attachments: |
|
Description
Truitt Savell
2020-11-16 12:04:56 PST
Created attachment 414263 [details]
001-crash-log.txt
Created attachment 414264 [details]
001-vertical-crash-log.txt
This is probably related to https://trac.webkit.org/changeset/269774/webkit I can reproduce these crashes with command: run-webkit-tests --iterations 2000 --exit-after-n-failures 1 --exit-after-n-crashes-or-timeouts 10 --debug-rwt-logging --no-retry --force --no-build -f fast/lists/001-vertical.html fast/lists/001.html marked these as skip on Mac wk2 while this is investigated: https://trac.webkit.org/changeset/269964/webkit Created attachment 416148 [details]
Patch
Comment on attachment 416148 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=416148&action=review > Source/WebCore/rendering/RenderListItem.cpp:65 > - auto markerStyle = getCachedPseudoStyle(PseudoId::Marker, &style()); > - ASSERT(markerStyle); > - return RenderStyle::clone(*markerStyle); > + if (auto markerStyle = getCachedPseudoStyle(PseudoId::Marker, &style())) > + return RenderStyle::clone(*markerStyle); There is an universal ::marker rule on UA sheet. It should never compute null. You should look into. why this is happening. Maybe it is being optimized away by one of the check in TreeResolver::resolvePseudoStyle? By the way, this crash is easily reproducible for me with just this command: run-webkit-tests --debug -1 --no-build fast/lists/001.html Interestingly, this crash can be reduced to just <div style="display: list-item"></div>, but <li></li> won't crash. Antti helped me figure this out, this is due to simpleUserAgentStyleSheet being used in these test cases and the ::marker UA style not being used. Created attachment 416260 [details]
patch
Created attachment 416265 [details]
patch
Committed r270886: <https://trac.webkit.org/changeset/270886> All reviewed patches have been landed. Closing bug and clearing flags on attachment 416265 [details]. |