Bug 24325

Summary: Crash on replacing document contents during drop
Product: WebKit Reporter: Scott Violet <sky>
Component: WebCore Misc.Assignee: Nobody <webkit-unassigned>
Severity: Normal    
Priority: P2    
Version: 528+ (Nightly build)   
Hardware: PC   
OS: Windows XP   
Description Flags
Fix for 24325
Fix for 24325 eric: review+

Description Scott Violet 2009-03-03 09:48:15 PST
I came across this when tracking down another crash. If you have a DOM mutation event listener and it replaces the entire contents of the document during a drop, we crash. I know, this is contrived, but it's a crash none the less.
Comment 1 Scott Violet 2009-03-03 09:53:38 PST
Created attachment 28226 [details]
Fix for 24325
Comment 2 Eric Seidel (no email) 2009-03-03 11:53:39 PST
Comment on attachment 28226 [details]
Fix for 24325

This looks fine.  I'm surprised that the test case needs to use waitUntilDone()

Ideally the test case should also set the text to PASSED when it's done.  The blank page would confuse me at first.
Comment 3 Scott Violet 2009-03-03 12:26:48 PST
Created attachment 28234 [details]
Fix for 24325

Changes output to be PASSED and removes waitForDone/NotifyDone.
Comment 4 Eric Seidel (no email) 2009-03-03 12:28:11 PST
Comment on attachment 28234 [details]
Fix for 24325

Looks fine.
Comment 5 Dimitri Glazkov (Google) 2009-03-03 13:13:17 PST
Landed as http://trac.webkit.org/changeset/41403.