There's no check on parentNode->renderer() before its used within canBeScrolledIntoView.
Associated Chromium fix with layout test https://chromium-review.googlesource.com/c/chromium/src/+/550255
Adding the following in the for loop fixes the problem.
+ if (UNLIKELY(!parentNode->renderer()))
Its EOD here so if nobody gets to this by Monday I'll just throw together a patch with the layout test in it.
Created attachment 348361 [details]
Port of the chromium fix
Comment on attachment 348361 [details]
View in context: https://bugs.webkit.org/attachment.cgi?id=348361&action=review
> + if (UNLIKELY(!parentNode->renderer()))
The UNLIKELY() seems unnecessary.
Created attachment 348371 [details]
Address review comments
Comment on attachment 348371 [details]
Clearing flags on attachment: 348371
Committed r235457: <https://trac.webkit.org/changeset/235457>
All reviewed patches have been landed. Closing bug.