Bug 85202 - WebCore::SVGAnimateMotionElement::applyResultsToTarget crash
: WebCore::SVGAnimateMotionElement::applyResultsToTarget crash
Status: RESOLVED FIXED
Product: WebKit
Classification: Unclassified
Component: SVG
: 528+ (Nightly build)
: Unspecified Unspecified
: P2 Normal
Assigned To: Nobody
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-04-30 09:22 PDT by Philip Rogers
Modified: 2012-05-01 09:10 PDT (History)
2 users (show)

See Also:


Attachments
Repro case (222 bytes, image/svg+xml)
2012-04-30 09:22 PDT, Philip Rogers
no flags Details
Skip building instance tree for disallowed target (7.13 KB, patch)
2012-04-30 10:28 PDT, Philip Rogers
no flags Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Philip Rogers 2012-04-30 09:22:04 PDT
Created attachment 139461 [details]
Repro case

As the title says, we can crash in WebCore::SVGAnimateMotionElement::applyResultsToTarget. See the attached svg file for a repro.

Original bug: crbug.com/124575
Comment 1 Philip Rogers 2012-04-30 10:28:36 PDT
Created attachment 139471 [details]
Skip building instance tree for disallowed target

My first foray into the shadow tree :)
Comment 2 Nikolas Zimmermann 2012-05-01 07:41:41 PDT
Comment on attachment 139471 [details]
Skip building instance tree for disallowed target

Ah great, r=me.
Comment 3 WebKit Review Bot 2012-05-01 09:09:54 PDT
Comment on attachment 139471 [details]
Skip building instance tree for disallowed target

Clearing flags on attachment: 139471

Committed r115730: <http://trac.webkit.org/changeset/115730>
Comment 4 WebKit Review Bot 2012-05-01 09:10:08 PDT
All reviewed patches have been landed.  Closing bug.