Summary: | crashes in WebProcess at WebCore::Range::startPosition const + 16 | ||||||
---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Enrica Casucci <enrica> | ||||
Component: | WebKit2 | Assignee: | Enrica Casucci <enrica> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | Normal | Keywords: | InRadar, PlatformOnly | ||||
Priority: | P2 | ||||||
Version: | 528+ (Nightly build) | ||||||
Hardware: | PC | ||||||
OS: | OS X 10.5 | ||||||
Attachments: |
|
Description
Enrica Casucci
2011-02-11 10:47:06 PST
Created attachment 82143 [details]
patch
Comment on attachment 82143 [details]
patch
We would be so much better off if we had a test case for this. When can convertToRange return 0? Maybe that will give us an idea how to reproduce.
(In reply to comment #2) > (From update of attachment 82143 [details]) > We would be so much better off if we had a test case for this. When can convertToRange return 0? Maybe that will give us an idea how to reproduce. I verified that we have regression tests for WebKit to test this scenario, but they are not enabled for WebKit2. platform/mac/editing/input/firstrectforcharacterrange-plain.html platform/mac/editing/input/firstrectforcharacterrange-styled.html produce the exact same crash signature when I run them with a version of WebKit with the null check removed. |