Bug 22454 - REGRESSION (3.2-TOT): Crash below FontFallbackList::fontDataAt on jacobian.org
Summary: REGRESSION (3.2-TOT): Crash below FontFallbackList::fontDataAt on jacobian.org
Status: RESOLVED FIXED
Alias: None
Product: WebKit
Classification: Unclassified
Component: WebCore Misc. (show other bugs)
Version: 528+ (Nightly build)
Hardware: Macintosh Intel OS X 10.5
: P1 Normal
Assignee: mitz
URL: http://jacobian.org/writing/merquery/
Keywords: InRadar, NeedsReduction, Regression
: 21467 22406 (view as bug list)
Depends on:
Blocks:
 
Reported: 2008-11-24 06:11 PST by Johan Bergström
Modified: 2010-09-12 22:31 PDT (History)
4 users (show)

See Also:


Attachments
crash log (28.61 KB, text/plain)
2008-11-24 06:12 PST, Johan Bergström
no flags Details
Avoid a style recalc while font tables are in an inconsistent state (5.88 KB, patch)
2008-11-27 15:30 PST, mitz
ap: review+
Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Johan Bergström 2008-11-24 06:11:45 PST
Webkit r38699 on Leopard 10.5.5 crashes when visiting mentioned web page. Crash log attached.
Comment 1 Johan Bergström 2008-11-24 06:12:52 PST
Created attachment 25425 [details]
crash log
Comment 2 Mark Rowe (bdash) 2008-11-24 06:14:50 PST
This doesn't crash for me with the same build.

The crash is happening at FontFallbackList.cpp:103, when calling FontData::isLoading.  It appears that the pure-virtual version of the function is being invoked, resulting in a jump to 0x0.  It's not clear how this can happen.
Comment 3 mitz 2008-11-27 11:22:05 PST
<rdar://problem/6405550>
Comment 4 mitz 2008-11-27 15:30:24 PST
Created attachment 25561 [details]
Avoid a style recalc while font tables are in an inconsistent state
Comment 5 mitz 2008-11-29 13:21:53 PST
*** Bug 22406 has been marked as a duplicate of this bug. ***
Comment 6 Alexey Proskuryakov 2008-11-29 13:32:38 PST
Comment on attachment 25561 [details]
Avoid a style recalc while font tables are in an inconsistent state

r=me, but please consider adding some comments, as discussed on IRC.
Comment 7 mitz 2008-11-29 13:40:59 PST
Fixed in r38843 <http://trac.webkit.org/changeset/38843>.
Comment 8 Johan Bergström 2008-12-01 13:17:46 PST
If it should matter - works for me, thanks.
Comment 9 Yuzo Fujishima 2010-09-12 22:31:30 PDT
*** Bug 21467 has been marked as a duplicate of this bug. ***