Crashes under RenderLayer::hitTestLayer under determinePrimarySnapshottedPlugIn()
Created attachment 246504 [details] Patch
Comment on attachment 246504 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=246504&action=review > Source/WebCore/page/FrameView.cpp:2577 > + for (auto& widget : children()) { const auto&? > Source/WebCore/page/FrameView.cpp:4008 > + // A child frame may have dirtied us during its layout. This is what frame flattening does and by judging the assertion above, it manages to resolve it without the extra layout. How is it different from that setup? > Source/WebCore/page/FrameView.h:125 > + bool needsStyleRecalcOrLayout(bool includeSubframes = true) const; We never call this function with includeSubframes = false; Could we drop this parameter?
https://trac.webkit.org/r180063