http://code.google.com/p/chromium/issues/detail?id=41494 --- Repro --------------------------------------------------------------- <object>x</object> <script> document.execCommand("SelectAll", false); document.designMode = "on"; document.execCommand("InsertNewlineInQuotedContent"); </script> --- Details ------------------------------------------------------------- id: WebCore::Position::getInlineBoxAndOffset RecursionSOV (2ff151b84dcc5cb5ce97a6de6d406158) description: Recursive function call in WebCore::Position::getInlineBoxAndOffset: 13548 loops stack: WebCore::positionInParentBeforeNode WebCore::PositionIterator::operator WebCore::Position WebCore::Position::upstream -- Start of 13548 loops -- WebCore::Position::getInlineBoxAndOffset -- End of loop -- WebCore::rootBoxForLine WebCore::startPositionForLine WebCore::startOfLine WebCore::isStartOfLine WebCore::Position::previousCharacterPosition WebCore::Position::leadingWhitespacePosition WebCore::DeleteSelectionCommand::initializePositionData WebCore::DeleteSelectionCommand::doApply WebCore::EditCommand::apply WebCore::CompositeEditCommand::applyCommandToComposite WebCore::CompositeEditCommand::deleteSelection WebCore::BreakBlockquoteCommand::doApply WebCore::EditCommand::apply WebCore::CompositeEditCommand::applyCommandToComposite WebCore::TypingCommand::insertParagraphSeparatorInQuotedContent WebCore::EditCommand::apply WebCore::applyCommand WebCore::TypingCommand::insertParagraphSeparatorInQuotedContent WebCore::executeInsertNewlineInQuotedContent WebCore::Editor::Command::execute WebCore::Document::execCommand WebCore::DocumentInternal::execCommandCallback v8::internal::HandleApiCallHelper<...> v8::internal::Builtin_HandleApiCall v8::internal::Invoke v8::internal::Execution::Call v8::Script::Run WebCore::V8Proxy::runScript WebCore::V8Proxy::evaluate WebCore::ScriptController::evaluate WebCore::ScriptController::executeScript WebCore::HTMLTokenizer::scriptExecution WebCore::HTMLTokenizer::scriptHandler WebCore::HTMLTokenizer::parseNonHTMLText WebCore::HTMLTokenizer::parseTag WebCore::HTMLTokenizer::write WebCore::FrameLoader::write WebCore::FrameLoader::endIfNotLoadingMainResource WebCore::FrameLoader::finishedLoading WebCore::MainResourceLoader::didFinishLoading WebCore::ResourceLoader::didFinishLoading webkit_glue::WebURLLoaderImpl::Context::OnCompletedRequest ...etc...
fixed in r59516 http://trac.webkit.org/changeset/59516/trunk