Bug 225677

Summary: AX: Crash at WebCore::Document::updateLayout
Product: WebKit Reporter: chris fleizach <cfleizach>
Component: AccessibilityAssignee: chris fleizach <cfleizach>
Status: RESOLVED FIXED    
Severity: Normal CC: aboxhall, apinheiro, dmazzoni, ews-watchlist, jcraig, jdiggs, samuel_white, webkit-bug-importer, zalan
Priority: P2 Keywords: InRadar
Version: WebKit Nightly Build   
Hardware: All   
OS: All   
Attachments:
Description Flags
patch none

Description chris fleizach 2021-05-11 15:58:25 PDT
50 WebCore: WTFCrashWithInfo(int, char const*, char const*, int)
        50 WebCore: WebCore::Document::updateLayout()
   ==> 50 WebCore: WebCore::AccessibilityObject::updateBackingStore() <==
            50 WebCore: -[WebAccessibilityObjectWrapperBase updateObjectBackingStore]
              50 WebCore: -[WebAccessibilityObjectWrapper accessibilityIsIgnored]
                50 AppKit: __NSAccessibilityEntryPointIsAccessibilityElement_block_invoke
                  50 AppKit: NSAccessibilityPerformEntryPointBOOL
                    50 AppKit: NSAccessibilityEntryPointIsAccessibilityElement
                      50 AppKit: NSAccessibilityPostNotificationForObservedElementWithUserInfo
                        50 WebCore: WebCore::AccessibilityMenuList::didUpdateActiveOption(int)
                          50 WebCore: WebCore::RenderMenuList::setTextFromOption(int)
                            50 WebCore: WebCore::HTMLSelectElement::selectOption(int, unsigned int)
                              50 WebCore: WebCore::HTMLOptionElement::insertedIntoAncestor(WebCore::Node::InsertionType, WebCore::ContainerNode&)
                                50 WebCore: WebCore::notifyNodeInsertedIntoDocument(WebCore::ContainerNode&, WebCore::Node&, WebCore::TreeScopeChange, WTF::Vector<WTF::Ref<WebCore::Node, WTF::DumbPtrTraits<WebCore::Node> >, 11ul, WTF::CrashOnOverflow, 16ul, WTF::FastMalloc>&)
                                  50 WebCore: WebCore::notifyChildNodeInserted(WebCore::ContainerNode&, WebCore::Node&)
                                    26 WebCore: WebCore::ContainerNode::appendChildWithoutPreInsertionValidityCheck(WebCore::Node&)
                                    | 24 WebCore: WebCore::Node::appendChild(WebCore::Node&)
                                    | | 24 WebCore: WebCore::jsNodePrototypeFunctionAppendChild(JSC::JSGlobalObject*, JSC::CallFrame*)


<rdar://problem/74472851>
Comment 1 chris fleizach 2021-05-12 17:14:30 PDT
Created attachment 428436 [details]
patch
Comment 2 EWS 2021-05-13 07:30:30 PDT
Committed r277434 (237682@main): <https://commits.webkit.org/237682@main>

All reviewed patches have been landed. Closing bug and clearing flags on attachment 428436 [details].