Bug 36800

Summary: Ownerless nodes leads a crash on DOMSelection APIs
Product: WebKit Reporter: Hajime Morrita <morrita>
Component: HTML EditingAssignee: Nobody <webkit-unassigned>
Severity: Normal    
Priority: P2    
Version: 528+ (Nightly build)   
Hardware: PC   
OS: OS X 10.5   
Description Flags
to reproduce none

Description Hajime Morrita 2010-03-29 19:25:24 PDT
Passing ownerless node to DOMSelection APIs including collapse(), extend(), selectAllChildren(), setPosition() causes a crash.
One type of ownerless node is newly-created DocumentType object.
This is similar to Bug 31680 and the fix on Bug 31680 will fix these. But we need regressions for that.
Comment 1 Hajime Morrita 2010-03-30 02:40:28 PDT
Created attachment 52015 [details]
to reproduce
Comment 2 Hajime Morrita 2010-04-01 22:33:17 PDT
Fixed at http://trac.webkit.org/changeset/56962