Created attachment 134125 [details] Repro case, crashes When a malformed SVG document puts a text element inside an animation element, like this <html> <head> <script type="application/javascript"> function test() { document.getElementById("crash").getTransformToElement(); } </script> </head> <body> <svg xmlns="http://www.w3.org/2000/svg" version="1.1" onload="test()"> <animateTransform > <text id="crash"> </text> </animateTransform> </svg> </body> </html> there is a crash because the text element does not have a renderer (it is an orphan, it seems, because animateTransform elements do not have rendered children) and this causes a crash when getCTM calls SVGTextElement::animatedLocalTransform().
Created attachment 134128 [details] Patch
Comment on attachment 134128 [details] Patch r=me.
Comment on attachment 134128 [details] Patch Clearing flags on attachment: 134128 Committed r112394: <http://trac.webkit.org/changeset/112394>
All reviewed patches have been landed. Closing bug.
Just FYI, I checked the other implementations of animatedLocalTransform(). There is only one, in SVGStyledTransformableElement, and it already had the exact check I added. Maybe in the future we should require that changes to implementations of a method check for all other implementations to see if they need the same fix. We can just raise the issue in reviews.
*** Bug 81992 has been marked as a duplicate of this bug. ***