Summary: | NULL pointer crash in TextIterator::handleTextBox() | ||||||
---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Thomas Sepez <tsepez> | ||||
Component: | CSS | Assignee: | Nobody <webkit-unassigned> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | Normal | CC: | commit-queue, eric, mitz | ||||
Priority: | P2 | ||||||
Version: | 528+ (Nightly build) | ||||||
Hardware: | All | ||||||
OS: | OS X 10.6 | ||||||
Attachments: |
|
Description
Thomas Sepez
2011-01-27 16:39:43 PST
Created attachment 80378 [details]
Proposed patch to check for empty vector as above.
Comment on attachment 80378 [details] Proposed patch to check for empty vector as above. View in context: https://bugs.webkit.org/attachment.cgi?id=80378&action=review Looks sane. > Source/WebCore/editing/TextIterator.cpp:546 > + InlineTextBox* firstTextBox = renderer->containsReversedText() ? (m_sortedTextBoxes.isEmpty() ? 0 : m_sortedTextBoxes[0]) : renderer->firstTextBox(); vector really wants a version of it's .at() call which can handle oversized indicies and return a defautl value. Being our rtl guy, mitz might want to see this go by. Comment on attachment 80378 [details] Proposed patch to check for empty vector as above. Clearing flags on attachment: 80378 Committed r76987: <http://trac.webkit.org/changeset/76987> All reviewed patches have been landed. Closing bug. |