Created attachment 147736 [details] Repro Selects from LIST 1 to LIST 3, then press 'delete'. render_widget_host_view_gtk.cc(929): pos + n <= text.length() This is actual DCHECK in chromium, but WebKit might (or might not) have a bug. So file this bug here anyway.
Though DRT does not crash in this test, but it behaves weird.
Created attachment 149364 [details] Patch
Indeed it was a bug in WebCore not in chromium.
Comment on attachment 149364 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=149364&action=review > LayoutTests/editing/shadow/delete-list-in-shadow-expected.txt:5 > +AB345 Can we replace this by PASS?
Maybe we should just replace all these rendererIsEditable by isContentEditable because we keep hitting these crashes. There are 64 other places where we call rendererIsEditable instead of isContentEditable according to shinyak, and I'm not certain if it's really productive for us to wait until fuzzer finds a reduction for us.
Created attachment 149373 [details] Patch for landing
Comment on attachment 149373 [details] Patch for landing Clearing flags on attachment: 149373 Committed r121211: <http://trac.webkit.org/changeset/121211>
All reviewed patches have been landed. Closing bug.