Seems like r99849 missed a code path in CSSGrammar.y: CSSParser* p = static_cast<CSSParser*>(parser); if ($$) $$->appendMediaQuery(p->sinkFloatingMediaQuery($4)); p->updateLastMediaLine($$); ($$ can be null and we would crash in updateLastMediaLine) I had some bandwidth today so I reduced the crashes seen in the wild and came up with a small patch. I will attach it shortly.
Created attachment 114848 [details] Proposed fix: extend the NULL-check. Reduced test case from our top-most crashers as test-case.
Comment on attachment 114848 [details] Proposed fix: extend the NULL-check. Reduced test case from our top-most crashers as test-case. Clearing flags on attachment: 114848 Committed r100092: <http://trac.webkit.org/changeset/100092>
All reviewed patches have been landed. Closing bug.