Merge https://chromium.googlesource.com/chromium/blink/+/99afc9b55ce176b4f5fe053070e19dbebc1891a5 In SliderThumbElement::setPositionFromPoint, renderer() can be NULL after HTMLInputElement::setValueFromRenderer, which dispatches 'input' event. Also, make a local vairable 'input' a RefPtr just in case. http://crbug.com/248402 I reproduced the crash in ToT WebKit.
<rdar://problem/14763983>
Merging the patch isn't enough to fix crash/hang in WebKit. We'll need to investigate it further.
Created attachment 209119 [details] Fixes the bug
Comment on attachment 209119 [details] Fixes the bug ok
Comment on attachment 209119 [details] Fixes the bug Thanks for the review!
Comment on attachment 209119 [details] Fixes the bug Clearing flags on attachment: 209119 Committed r154308: <http://trac.webkit.org/changeset/154308>
All reviewed patches have been landed. Closing bug.