When a node inside a flow thread with no regions is highlighted, WebCore crashes. 0 com.apple.JavaScriptCore 0x0000000107c3dfaa WTFCrash + 42 1 com.apple.WebCore 0x0000000109faf8f4 WebCore::buildObjectForRendererFragments(WebCore::RenderObject*, WebCore::HighlightConfig const&) + 324 2 com.apple.WebCore 0x0000000109faf5be WebCore::InspectorOverlay::buildObjectForHighlightedNode() const + 494 3 com.apple.WebCore 0x0000000109faefe4 WebCore::InspectorOverlay::drawNodeHighlight() + 36 4 com.apple.WebCore 0x0000000109faeabe WebCore::InspectorOverlay::update() + 558 5 com.apple.WebCore 0x0000000109faecba WebCore::InspectorOverlay::highlightNode(WebCore::Node*, WebCore::HighlightConfig const&) + 106 6 com.apple.WebCore 0x0000000109f5af65 WebCore::InspectorDOMAgent::highlightNode(WTF::String*, WTF::RefPtr<WebCore::InspectorObject> const&, int const*, WTF::String const*) + 485 7 com.apple.WebCore 0x0000000109f5aff2 non-virtual thunk to WebCore::InspectorDOMAgent::highlightNode(WTF::String*, WTF::RefPtr<WebCore::InspectorObject> const&, int const*, WTF::String const*) + 82 8 com.apple.WebCore 0x0000000109ee13c1 WebCore::InspectorBackendDispatcherImpl::DOM_highlightNode(long, WebCore::InspectorObject*) + 785 9 com.apple.WebCore 0x0000000109ef6c7e WebCore::InspectorBackendDispatcherImpl::dispatch(WTF::String const&) + 1838 10 com.apple.WebCore 0x0000000109f0feb0 WebCore::InspectorController::dispatchMessageFromFrontend(WTF::String const&) + 96 11 com.apple.WebCore 0x0000000109f88afe WebCore::InspectorBackendDispatchTask::onTimer(WebCore::Timer<WebCore::InspectorBackendDispatchTask>*) + 110 12 com.apple.WebCore 0x0000000109f88ee3 WebCore::Timer<WebCore::InspectorBackendDispatchTask>::fired() + 115 13 com.apple.WebCore 0x000000010add4f13 WebCore::ThreadTimers::sharedTimerFiredInternal() + 307 14 com.apple.WebCore 0x000000010add4c29 WebCore::ThreadTimers::sharedTimerFired() + 25 15 com.apple.WebCore 0x000000010ab6f463 WebCore::timerFired(__CFRunLoopTimer*, void*) + 67 16 com.apple.CoreFoundation 0x00007fff894db804 __CFRUNLOOP_IS_CALLING_OUT_TO_A_TIMER_CALLBACK_FUNCTION__ + 20 17 com.apple.CoreFoundation 0x00007fff894db31d __CFRunLoopDoTimer + 557 18 com.apple.CoreFoundation 0x00007fff894c0ad9 __CFRunLoopRun + 1529 19 com.apple.CoreFoundation 0x00007fff894c00e2 CFRunLoopRunSpecific + 290 20 DumpRenderTree 0x000000010750a0c0 runTest(std::__1::basic_string<char, std::__1::char_traits<char>, std::__1::allocator<char> > const&) + 4912 (DumpRenderTree.mm:1415) 21 DumpRenderTree 0x0000000107508d1a runTestingServerLoop() + 282 (DumpRenderTree.mm:861) 22 DumpRenderTree 0x0000000107508705 dumpRenderTree(int, char const**) + 405 (DumpRenderTree.mm:916) 23 DumpRenderTree 0x000000010750a978 main + 296 (DumpRenderTree.mm:959) 24 libdyld.dylib 0x00007fff8c0347e1 start + 1
<rdar://problem/15255110>
Created attachment 214510 [details] Patch V1
Comment on attachment 214510 [details] Patch V1 View in context: https://bugs.webkit.org/attachment.cgi?id=214510&action=review r=me > LayoutTests/inspector-protocol/dom/highlight-flow-with-no-region.html:19 > + if (msg.error) { > + InspectorTest.log(msg.error.message); > + InspectorTest.completeTest(); > + return; > + } I created a helper for this in LayoutTests/http/tests/inspector-protocol/resources/InspectorTest.js named InspectorTest.checkForError: InspectorTest.checkForError = function(responseObject) { if (responseObject.error) { InspectorTest.log("PROTOCOL ERROR: " + responseObject.error.message); InspectorTest.completeTest(); throw "PROTOCOL ERROR"; } } So instead of these if blocks you can just do: InspectorTest.checkForError(msg);
Created attachment 214514 [details] Patch V2 Thanks!
Comment on attachment 214514 [details] Patch V2 Clearing flags on attachment: 214514 Committed r157605: <http://trac.webkit.org/changeset/157605>
All reviewed patches have been landed. Closing bug.