After fix for https://bugs.webkit.org/show_bug.cgi?id=120769, positionForPoint for a region attempt to use the associated named flow to perform its task. However, this should happen only when the region is valid. If the region is invalid, part of a region chain, positionForPoint should behave as usual for a block, otherwise it may run into an infinite loop, which eventually leads to a crash.
Created attachment 219840 [details] Patch
Comment on attachment 219840 [details] Patch r=me
Comment on attachment 219840 [details] Patch Clearing flags on attachment: 219840 Committed r160979: <http://trac.webkit.org/changeset/160979>
All reviewed patches have been landed. Closing bug.