Bug 76258 - NULL ptr in WebCore::ContainerNode::parserAddChild
Summary: NULL ptr in WebCore::ContainerNode::parserAddChild
Status: RESOLVED FIXED
Alias: None
Product: WebKit
Classification: Unclassified
Component: HTML Editing (show other bugs)
Version: 528+ (Nightly build)
Hardware: PC Windows Vista
: P1 Normal
Assignee: Adam Barth
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-01-13 02:04 PST by Berend-Jan Wever
Modified: 2012-01-26 17:55 PST (History)
5 users (show)

See Also:


Attachments
Repro (348 bytes, text/html)
2012-01-13 02:04 PST, Berend-Jan Wever
no flags Details
Patch (4.32 KB, patch)
2012-01-26 16:52 PST, Adam Barth
no flags Details | Formatted Diff | Diff
Patch for landing (4.31 KB, patch)
2012-01-26 16:55 PST, Adam Barth
no flags Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Berend-Jan Wever 2012-01-13 02:04:04 PST
Created attachment 122396 [details]
Repro

Chromium: http://code.google.com/p/chromium/issues/detail?id=110146

Repro:

x<h4><strike>x

<script>
  window.onload=function(){
    document.execCommand("SelectAll");
    document.designMode="on";
    document.execCommand("Indent");
    document.execCommand("InsertOrderedList", false);
  };
  document.addEventListener("DOMSubtreeModified",function(){
    document.execCommand("outdent", false);
  },false);
</script>
Comment 1 Adam Barth 2012-01-26 16:12:08 PST
I can reproduce the crash.
Comment 2 Adam Barth 2012-01-26 16:52:13 PST
Created attachment 124216 [details]
Patch
Comment 3 Eric Seidel (no email) 2012-01-26 16:54:59 PST
Comment on attachment 124216 [details]
Patch

OK.
Comment 4 Adam Barth 2012-01-26 16:55:55 PST
Created attachment 124218 [details]
Patch for landing
Comment 5 WebKit Review Bot 2012-01-26 17:55:54 PST
Comment on attachment 124218 [details]
Patch for landing

Clearing flags on attachment: 124218

Committed r106072: <http://trac.webkit.org/changeset/106072>
Comment 6 WebKit Review Bot 2012-01-26 17:55:58 PST
All reviewed patches have been landed.  Closing bug.