<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[166736] trunk</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://trac.webkit.org/projects/webkit/changeset/166736">166736</a></dd>
<dt>Author</dt> <dd>hyatt@apple.com</dd>
<dt>Date</dt> <dd>2014-04-03 12:22:48 -0700 (Thu, 03 Apr 2014)</dd>
</dl>

<h3>Log Message</h3>
<pre>Continuations casting issue.
https://bugs.webkit.org/show_bug.cgi?id=130057
&lt;rdar://problem/16283406&gt;

Reviewed by Simon Fraser.

Source/WebCore: 

The code to update relative positioned anonymous block continuations should not
have assumed that all siblings were RenderBlocks. Make the code smarter and
make it bail when it hits something that isn't part of the block continuation
chain.

Added fast/block/continuation-crash.html

* rendering/RenderInline.cpp:
(WebCore::updateStyleOfAnonymousBlockContinuations):

LayoutTests: 

* fast/block/continuation-crash-expected.txt: Added.
* fast/block/continuation-crash.html: Added.</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunkLayoutTestsChangeLog">trunk/LayoutTests/ChangeLog</a></li>
<li><a href="#trunkSourceWebCoreChangeLog">trunk/Source/WebCore/ChangeLog</a></li>
<li><a href="#trunkSourceWebCorerenderingRenderInlinecpp">trunk/Source/WebCore/rendering/RenderInline.cpp</a></li>
</ul>

<h3>Added Paths</h3>
<ul>
<li><a href="#trunkLayoutTestsfastblockcontinuationcrashexpectedtxt">trunk/LayoutTests/fast/block/continuation-crash-expected.txt</a></li>
<li><a href="#trunkLayoutTestsfastblockcontinuationcrashhtml">trunk/LayoutTests/fast/block/continuation-crash.html</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunkLayoutTestsChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/LayoutTests/ChangeLog (166735 => 166736)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/LayoutTests/ChangeLog        2014-04-03 19:01:28 UTC (rev 166735)
+++ trunk/LayoutTests/ChangeLog        2014-04-03 19:22:48 UTC (rev 166736)
</span><span class="lines">@@ -1,3 +1,14 @@
</span><ins>+2014-04-03  David Hyatt  &lt;hyatt@apple.com&gt;
+
+        Continuations casting issue.
+        https://bugs.webkit.org/show_bug.cgi?id=130057
+        &lt;rdar://problem/16283406&gt;
+
+        Reviewed by Simon Fraser.
+
+        * fast/block/continuation-crash-expected.txt: Added.
+        * fast/block/continuation-crash.html: Added.
+
</ins><span class="cx"> 2014-04-03  Zoltan Horvath  &lt;zoltan@webkit.org&gt;
</span><span class="cx"> 
</span><span class="cx">         [WebInspector] inspector/dom/highlight-shape-outside-margin.html is failing
</span><span class="lines">@@ -1960,7 +1971,7 @@
</span><span class="cx">         Crash in RenderBlock::addChildIgnoringAnonymousColumnBlocks.
</span><span class="cx">         https://bugs.webkit.org/show_bug.cgi?id=129948
</span><span class="cx">         &lt;rdar://problem/16074072&gt;
</span><del>-        
</del><ins>+
</ins><span class="cx">         Reviewed by Simon Fraser.
</span><span class="cx"> 
</span><span class="cx">         * fast/multicol/multicol-li-crash-expected.txt: Added.
</span></span></pre></div>
<a id="trunkLayoutTestsfastblockcontinuationcrashexpectedtxt"></a>
<div class="addfile"><h4>Added: trunk/LayoutTests/fast/block/continuation-crash-expected.txt (0 => 166736)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/LayoutTests/fast/block/continuation-crash-expected.txt                                (rev 0)
+++ trunk/LayoutTests/fast/block/continuation-crash-expected.txt        2014-04-03 19:22:48 UTC (rev 166736)
</span><span class="lines">@@ -0,0 +1,2 @@
</span><ins>+This test passes if it does not crash.
+
</ins></span></pre></div>
<a id="trunkLayoutTestsfastblockcontinuationcrashhtml"></a>
<div class="addfile"><h4>Added: trunk/LayoutTests/fast/block/continuation-crash.html (0 => 166736)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/LayoutTests/fast/block/continuation-crash.html                                (rev 0)
+++ trunk/LayoutTests/fast/block/continuation-crash.html        2014-04-03 19:22:48 UTC (rev 166736)
</span><span class="lines">@@ -0,0 +1,23 @@
</span><ins>+&lt;style&gt;
+#span2
+{ position: relative; }
+&lt;/style&gt;
+ &lt;script&gt;
+function run() {
+        document.getElementById(&quot;span2&quot;).style.position = &quot;static&quot;;
+}
+&lt;/script&gt;
+&lt;body&gt;
+This test passes if it does not crash.
+&lt;span id=&quot;span2&quot;&gt;
+&lt;div&gt;&lt;/div&gt;
+&lt;script&gt;
+try {
+var x = window.getSelection();
+x.getRangeAt(document.body.appendChild(document.createElement(&quot;frame&quot;)).height);
+} catch (e) {}
+document.body.offsetWidth
+run()
+if (window.testRunner)
+    testRunner.dumpAsText()
+&lt;/script&gt;
</ins><span class="cx">\ No newline at end of file
</span></span></pre></div>
<a id="trunkSourceWebCoreChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/Source/WebCore/ChangeLog (166735 => 166736)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/WebCore/ChangeLog        2014-04-03 19:01:28 UTC (rev 166735)
+++ trunk/Source/WebCore/ChangeLog        2014-04-03 19:22:48 UTC (rev 166736)
</span><span class="lines">@@ -1,3 +1,21 @@
</span><ins>+2014-04-03  David Hyatt  &lt;hyatt@apple.com&gt;
+
+        Continuations casting issue.
+        https://bugs.webkit.org/show_bug.cgi?id=130057
+        &lt;rdar://problem/16283406&gt;
+
+        Reviewed by Simon Fraser.
+
+        The code to update relative positioned anonymous block continuations should not
+        have assumed that all siblings were RenderBlocks. Make the code smarter and
+        make it bail when it hits something that isn't part of the block continuation
+        chain.
+
+        Added fast/block/continuation-crash.html
+
+        * rendering/RenderInline.cpp:
+        (WebCore::updateStyleOfAnonymousBlockContinuations):
+
</ins><span class="cx"> 2014-04-03  Bem Jones-Bey  &lt;bjonesbe@adobe.com&gt;
</span><span class="cx"> 
</span><span class="cx">         [CSS Shapes] CRASH with calc() value args in inset round
</span></span></pre></div>
<a id="trunkSourceWebCorerenderingRenderInlinecpp"></a>
<div class="modfile"><h4>Modified: trunk/Source/WebCore/rendering/RenderInline.cpp (166735 => 166736)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/WebCore/rendering/RenderInline.cpp        2014-04-03 19:01:28 UTC (rev 166735)
+++ trunk/Source/WebCore/rendering/RenderInline.cpp        2014-04-03 19:22:48 UTC (rev 166736)
</span><span class="lines">@@ -143,11 +143,19 @@
</span><span class="cx">     return 0;
</span><span class="cx"> }
</span><span class="cx"> 
</span><del>-static void updateStyleOfAnonymousBlockContinuations(RenderBlock* block, const RenderStyle* newStyle, const RenderStyle* oldStyle)
</del><ins>+static void updateStyleOfAnonymousBlockContinuations(RenderBox* box, const RenderStyle* newStyle, const RenderStyle* oldStyle)
</ins><span class="cx"> {
</span><del>-    for (;block &amp;&amp; block-&gt;isAnonymousBlock(); block = toRenderBlock(block-&gt;nextSibling())) {
-        if (!block-&gt;isAnonymousBlockContinuation() || block-&gt;style().position() == newStyle-&gt;position())
</del><ins>+    for (;box &amp;&amp; box-&gt;isAnonymousBlock(); box = box-&gt;nextSiblingBox()) {
+        if (box-&gt;style().position() == newStyle-&gt;position())
</ins><span class="cx">             continue;
</span><ins>+        
+        if (!box-&gt;isRenderBlock())
+            break; // We're done if we ever encounter something other than a RenderBlock.
+
+        RenderBlock* block = toRenderBlock(box);
+        if (!block-&gt;isAnonymousBlockContinuation())
+            break; // We're done if we ever encounter something other than a continuation RenderBlock.
+        
</ins><span class="cx">         // If we are no longer in-flow positioned but our descendant block(s) still have an in-flow positioned ancestor then
</span><span class="cx">         // their containing anonymous block should keep its in-flow positioning. 
</span><span class="cx">         RenderInline* cont = block-&gt;inlineElementContinuation();
</span></span></pre>
</div>
</div>

</body>
</html>