Summary: | REGRESSION(81035): crash in RenderDetails::removeChild | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | James Robinson <jamesr> | ||||||||
Component: | Layout and Rendering | Assignee: | Luiz Agostini <luiz> | ||||||||
Status: | RESOLVED FIXED | ||||||||||
Severity: | Normal | CC: | cmarcelo, commit-queue, dglazkov, hyatt, inferno, luiz, mitz, mrobinson, simon.fraser, webkit.review.bot | ||||||||
Priority: | P2 | Keywords: | InRadar | ||||||||
Version: | 528+ (Nightly build) | ||||||||||
Hardware: | PC | ||||||||||
OS: | OS X 10.5 | ||||||||||
URL: | http://runescape.wikia.com/wiki/Special:Search | ||||||||||
Bug Depends on: | 51071 | ||||||||||
Bug Blocks: | |||||||||||
Attachments: |
|
Description
James Robinson
2011-03-21 15:34:54 PDT
innerHTML is being set on a <section> that contains a <details> element. Here's the showTree() output for the node that innerHTML is being set on immediately before the crash: * SECTION 0x7fffc0e783f0 CLASS=WikiaPagesOnWikiModule module #text 0x7fffc0e7bf50 "\n " H1 0x7fffc0e78360 #text 0x7fffc0e7bee0 "Pages on RuneScape Wiki" #text 0x7fffc0e7be70 "\n " A 0x7fffc1f5f000 CLASS=wikia-button createpage IMG 0x7fffc0e7ec40 CLASS=sprite new #text 0x7fffc1473a80 "Add a Page" #text 0x7fffc1473a10 " " DETAILS 0x7fffc1474f00 CLASS=tally #text 0x7fffc1473770 "\n " EM 0x7fffc0e78240 #text 0x7fffc1473700 "17,135" SPAN 0x7fffc0e781b0 CLASS=fixedwidth #text 0x7fffc1473620 "pages on this wiki" #text 0x7fffc14735b0 " " #text 0x7fffc1473540 "\n" This introduced multiple security regressions including this one and another one in acccessibility code. See testcase in http://trac.webkit.org/changeset/81648 in Chrome. Luiz, can you please take a look. (In reply to comment #2) > This introduced multiple security regressions including this one and another one in acccessibility code. See testcase in http://trac.webkit.org/changeset/81648 in Chrome. > > Luiz, can you please take a look. Looking. Created attachment 86477 [details]
patch
Created attachment 86485 [details]
patch
bad spelling in changelog.
Comment on attachment 86485 [details]
patch
This needs at least one test
Created attachment 86499 [details]
patch
Comment on attachment 86499 [details]
patch
r=me
Comment on attachment 86499 [details] patch Clearing flags on attachment: 86499 Committed r81812: <http://trac.webkit.org/changeset/81812> All reviewed patches have been landed. Closing bug. |