It looks like FrameSelection::copyTypingStyle can return nil, but after r106681 -[WebFrame _typingStyle] assumes it does not.
<rdar://problem/10825155>
Created attachment 126001 [details] patch
Can you add a TestWebKitAPI test for this?
Created attachment 126100 [details] with API test
Comment on attachment 126100 [details] with API test View in context: https://bugs.webkit.org/attachment.cgi?id=126100&action=review > Tools/TestWebKitAPI/Tests/mac/TypingStyleCrash.mm:32 > + WebView *webView = [[WebView alloc] initWithFrame:NSZeroRect frameName:@"" groupName:@""]; I think another way to do the same thing is: [[WebView alloc] init]. I believe those arguments are the defaults.
Comment on attachment 126100 [details] with API test View in context: https://bugs.webkit.org/attachment.cgi?id=126100&action=review > Tools/ChangeLog:12 > + (TestWebKitAPI): prepare-ChangeLog keeps adding these… > Tools/TestWebKitAPI/Tests/mac/TypingStyleCrash.mm:33 > + [webView.mainFrame loadHTMLString:@"<html><body>foo</body></html>" baseURL:nil]; I doubt that this accomplishes anything, since you don’t spin the run loop and wait for this to load before continuing. Presumably, you can just remove this.
http://trac.webkit.org/changeset/107100