Bug found in latest Chrome 1.x release without symbols, so I have no stack dump or anything. It repro's reliably in latest Chrome 2.x ToT. Repro <SCRIPT> path = window.document.createElementNS("http://www.w3.org/2000/svg", "path"); path.getPresentationAttribute(""); </SCRIPT>
Added repro url.
Renaming to "SVG"
Created attachment 30021 [details] Fix mappedAttributes() access without NULL check 6 files changed, 41 insertions(+), 0 deletions(-)
Comment on attachment 30021 [details] Fix mappedAttributes() access without NULL check r=me
Thank you very much for the bug and excellent test case! Committing to http://svn.webkit.org/repository/webkit/trunk ... M LayoutTests/ChangeLog A LayoutTests/svg/custom/path-getPresentationAttribute-crash-expected.txt A LayoutTests/svg/custom/path-getPresentationAttribute-crash.html M WebCore/ChangeLog M WebCore/html/HTMLInputElement.cpp M WebCore/svg/SVGStyledElement.cpp Committed r43237