In the following document: <html> <head> <style> div { border-image: url(images/shadow-border.png) stretch 10; } </style> </head> <body> <div>FOO</div> </body> </html> Inspect the FOO div. A crash. The crashing line: case CSS_PAIR: text = m_value.pair->first()->cssText(); if (m_value.pair->second() != m_value.pair->first()) { text += " "; text += m_value.pair->second()->cssText(); // <------------- } This is due to CSSParser::parseBorderImageRepeat(RefPtr<CSSValue>& result) building a CSSPair with second() equal to 0 (last else-branch inside "if (val)" does not initialize secondValue). Upstreaming http://crbug.com/141139
Similar to bug 70105.
Created attachment 157117 [details] Repro that doesn't involve the inspector
I know what's going on, I have a patch.
Created attachment 157133 [details] Fix this bug
Created attachment 157136 [details] Fix quality English
Comment on attachment 157136 [details] Fix quality English Clearing flags on attachment: 157136 Committed r125016: <http://trac.webkit.org/changeset/125016>
All reviewed patches have been landed. Closing bug.