Add isfinite to childSize calculation in RenderFlexibleBox::resolveFlexibleLengths to avoid overflow.
Created attachment 180414 [details] Patch
Comment on attachment 180414 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=180414&action=review > Source/WebCore/ChangeLog:11 > + No new tests (OOPS!). Need to remove the OOPS. Maybe mention that this is covered by css3/flexbox/flex-algorithm.html. > Source/WebCore/rendering/RenderFlexibleBox.cpp:988 > + double extraSpace; I think you need to initialize this because it might not be set below.
(In reply to comment #2) > > Source/WebCore/rendering/RenderFlexibleBox.cpp:988 > > + double extraSpace; > > I think you need to initialize this because it might not be set below. Oops, glad you cough that!
Created attachment 180416 [details] Patch
Committed r138312: <http://trac.webkit.org/changeset/138312>