<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[175345] trunk</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://trac.webkit.org/projects/webkit/changeset/175345">175345</a></dd>
<dt>Author</dt> <dd>zalan@apple.com</dd>
<dt>Date</dt> <dd>2014-10-29 14:13:12 -0700 (Wed, 29 Oct 2014)</dd>
</dl>

<h3>Log Message</h3>
<pre>Remove invalid float from RootInlineBox.
https://bugs.webkit.org/show_bug.cgi?id=137707

Reviewed by Antti Koivisto.

In certain cases, floating boxes get attached to the last (root) inline box.
When this particular floating box gets destroyed, it also needs to be detached
from the last inline box.
Source/WebCore:

1. Introduce RootInlineBox::removeFloat() (vs. RootInlineBox::appendFloat())
2. Ensure that it is called when the floating box is being destroyed.

Test: fast/inline/crash-when-inline-box-has-invalid-float.html

* rendering/RenderBlockFlow.cpp:
(WebCore::RenderBlockFlow::removeFloatingObject):
(WebCore::RenderBlockFlow::markAllDescendantsWithFloatsForLayout): During style recalc, while
tearing down the render tree, we can get to a state where a block element has both inline and block children.
It happens when the style change on an element makes sibling anonymous block wrappers detached.
In that case the markAllDescendantsWithFloatsForLayout() call does not get propagated down on the
block child elements as we return early at the childrenInline() check.
* rendering/RootInlineBox.h:
(WebCore::RootInlineBox::removeFloat):

LayoutTests:

* fast/inline/crash-when-inline-box-has-invalid-float-expected.txt: Added.
* fast/inline/crash-when-inline-box-has-invalid-float.html: Added.</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunkLayoutTestsChangeLog">trunk/LayoutTests/ChangeLog</a></li>
<li><a href="#trunkSourceWebCoreChangeLog">trunk/Source/WebCore/ChangeLog</a></li>
<li><a href="#trunkSourceWebCorerenderingRenderBlockFlowcpp">trunk/Source/WebCore/rendering/RenderBlockFlow.cpp</a></li>
<li><a href="#trunkSourceWebCorerenderingRootInlineBoxh">trunk/Source/WebCore/rendering/RootInlineBox.h</a></li>
</ul>

<h3>Added Paths</h3>
<ul>
<li><a href="#trunkLayoutTestsfastinlinecrashwheninlineboxhasinvalidfloatexpectedtxt">trunk/LayoutTests/fast/inline/crash-when-inline-box-has-invalid-float-expected.txt</a></li>
<li><a href="#trunkLayoutTestsfastinlinecrashwheninlineboxhasinvalidfloathtml">trunk/LayoutTests/fast/inline/crash-when-inline-box-has-invalid-float.html</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunkLayoutTestsChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/LayoutTests/ChangeLog (175344 => 175345)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/LayoutTests/ChangeLog        2014-10-29 21:04:28 UTC (rev 175344)
+++ trunk/LayoutTests/ChangeLog        2014-10-29 21:13:12 UTC (rev 175345)
</span><span class="lines">@@ -1,3 +1,17 @@
</span><ins>+2014-10-29  Zalan Bujtas  &lt;zalan@apple.com&gt;
+
+        Remove invalid float from RootInlineBox.
+        https://bugs.webkit.org/show_bug.cgi?id=137707
+
+        Reviewed by Antti Koivisto.
+
+        In certain cases, floating boxes get attached to the last (root) inline box.
+        When this particular floating box gets destroyed, it also needs to be detached
+        from the last inline box.
+
+        * fast/inline/crash-when-inline-box-has-invalid-float-expected.txt: Added.
+        * fast/inline/crash-when-inline-box-has-invalid-float.html: Added.
+
</ins><span class="cx"> 2014-10-29  Alexey Proskuryakov  &lt;ap@apple.com&gt;
</span><span class="cx"> 
</span><span class="cx">         Update Mavericks results after https://bugs.webkit.org/show_bug.cgi?id=137275
</span></span></pre></div>
<a id="trunkLayoutTestsfastinlinecrashwheninlineboxhasinvalidfloatexpectedtxt"></a>
<div class="addfile"><h4>Added: trunk/LayoutTests/fast/inline/crash-when-inline-box-has-invalid-float-expected.txt (0 => 175345)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/LayoutTests/fast/inline/crash-when-inline-box-has-invalid-float-expected.txt                                (rev 0)
+++ trunk/LayoutTests/fast/inline/crash-when-inline-box-has-invalid-float-expected.txt        2014-10-29 21:13:12 UTC (rev 175345)
</span><span class="lines">@@ -0,0 +1,6 @@
</span><ins>+PASS, if no crash or ASSERT in debug. 
+
+
+
+
+BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBAAAAAAAAAAAAAAAAAAAAAA
</ins></span></pre></div>
<a id="trunkLayoutTestsfastinlinecrashwheninlineboxhasinvalidfloathtml"></a>
<div class="addfile"><h4>Added: trunk/LayoutTests/fast/inline/crash-when-inline-box-has-invalid-float.html (0 => 175345)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/LayoutTests/fast/inline/crash-when-inline-box-has-invalid-float.html                                (rev 0)
+++ trunk/LayoutTests/fast/inline/crash-when-inline-box-has-invalid-float.html        2014-10-29 21:13:12 UTC (rev 175345)
</span><span class="lines">@@ -0,0 +1,30 @@
</span><ins>+&lt;!DOCTYPE html&gt;
+&lt;html&gt;
+&lt;head&gt;
+&lt;title&gt;This tests that floating elments are cleaned up properly.&lt;/title&gt;
+&lt;style&gt;
+  :last-child {float:left;}
+&lt;/style&gt;
+&lt;/head&gt;
+
+&lt;body&gt;
+PASS, if no crash or ASSERT in debug.
+&lt;br&gt;
+&lt;br&gt;
+&lt;br&gt;
+&lt;article&gt;
+&lt;pre&gt;&lt;/pre&gt;
+&lt;br&gt;
+&lt;content&gt;
+&lt;br&gt;
+&lt;select&gt;&lt;/select&gt;
+&lt;script&gt;
+document.body.contentEditable = &quot;true&quot;;
+document.execCommand(&quot;SelectAll&quot;);
+document.execCommand(&quot;StrikeThrough&quot;);
+if (window.testRunner)
+        testRunner.dumpAsText();
+&lt;/script&gt;
+BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBAAAAAAAAAAAAAAAAAAAAAA
+&lt;/body&gt;
+&lt;/html&gt;
</ins><span class="cx">\ No newline at end of file
</span></span></pre></div>
<a id="trunkSourceWebCoreChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/Source/WebCore/ChangeLog (175344 => 175345)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/WebCore/ChangeLog        2014-10-29 21:04:28 UTC (rev 175344)
+++ trunk/Source/WebCore/ChangeLog        2014-10-29 21:13:12 UTC (rev 175345)
</span><span class="lines">@@ -1,3 +1,28 @@
</span><ins>+2014-10-29  Zalan Bujtas  &lt;zalan@apple.com&gt;
+
+        Remove invalid float from RootInlineBox.
+        https://bugs.webkit.org/show_bug.cgi?id=137707
+
+        Reviewed by Antti Koivisto.
+
+        In certain cases, floating boxes get attached to the last (root) inline box.
+        When this particular floating box gets destroyed, it also needs to be detached
+        from the last inline box.
+        1. Introduce RootInlineBox::removeFloat() (vs. RootInlineBox::appendFloat())
+        2. Ensure that it is called when the floating box is being destroyed.
+
+        Test: fast/inline/crash-when-inline-box-has-invalid-float.html
+
+        * rendering/RenderBlockFlow.cpp:
+        (WebCore::RenderBlockFlow::removeFloatingObject):
+        (WebCore::RenderBlockFlow::markAllDescendantsWithFloatsForLayout): During style recalc, while
+        tearing down the render tree, we can get to a state where a block element has both inline and block children.
+        It happens when the style change on an element makes sibling anonymous block wrappers detached.
+        In that case the markAllDescendantsWithFloatsForLayout() call does not get propagated down on the
+        block child elements as we return early at the childrenInline() check.
+        * rendering/RootInlineBox.h:
+        (WebCore::RootInlineBox::removeFloat):
+
</ins><span class="cx"> 2014-10-29  Antti Koivisto  &lt;antti@apple.com&gt;
</span><span class="cx"> 
</span><span class="cx">         Unreviewed, rolling out r175342.
</span></span></pre></div>
<a id="trunkSourceWebCorerenderingRenderBlockFlowcpp"></a>
<div class="modfile"><h4>Modified: trunk/Source/WebCore/rendering/RenderBlockFlow.cpp (175344 => 175345)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/WebCore/rendering/RenderBlockFlow.cpp        2014-10-29 21:04:28 UTC (rev 175344)
+++ trunk/Source/WebCore/rendering/RenderBlockFlow.cpp        2014-10-29 21:13:12 UTC (rev 175345)
</span><span class="lines">@@ -2225,6 +2225,7 @@
</span><span class="cx">                     logicalBottom = std::max(logicalBottom, logicalTop + 1);
</span><span class="cx">                 }
</span><span class="cx">                 if (floatingObject-&gt;originatingLine()) {
</span><ins>+                    floatingObject-&gt;originatingLine()-&gt;removeFloat(floatBox);
</ins><span class="cx">                     if (!selfNeedsLayout()) {
</span><span class="cx">                         ASSERT(&amp;floatingObject-&gt;originatingLine()-&gt;renderer() == this);
</span><span class="cx">                         floatingObject-&gt;originatingLine()-&gt;markDirty();
</span><span class="lines">@@ -2682,10 +2683,7 @@
</span><span class="cx">     if (floatToRemove)
</span><span class="cx">         removeFloatingObject(*floatToRemove);
</span><span class="cx"> 
</span><del>-    if (childrenInline())
-        return;
-
-    // Iterate over our children and mark them as needed.
</del><ins>+    // Iterate over our block children and mark them as needed.
</ins><span class="cx">     for (auto&amp; block : childrenOfType&lt;RenderBlock&gt;(*this)) {
</span><span class="cx">         if (!floatToRemove &amp;&amp; block.isFloatingOrOutOfFlowPositioned())
</span><span class="cx">             continue;
</span></span></pre></div>
<a id="trunkSourceWebCorerenderingRootInlineBoxh"></a>
<div class="modfile"><h4>Modified: trunk/Source/WebCore/rendering/RootInlineBox.h (175344 => 175345)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/WebCore/rendering/RootInlineBox.h        2014-10-29 21:04:28 UTC (rev 175344)
+++ trunk/Source/WebCore/rendering/RootInlineBox.h        2014-10-29 21:13:12 UTC (rev 175345)
</span><span class="lines">@@ -145,6 +145,13 @@
</span><span class="cx">             m_floats = std::make_unique&lt;Vector&lt;RenderBox*&gt;&gt;(1, &amp;floatingBox);
</span><span class="cx">     }
</span><span class="cx"> 
</span><ins>+    void removeFloat(RenderBox&amp; floatingBox)
+    {
+        ASSERT(m_floats);
+        ASSERT(m_floats-&gt;contains(&amp;floatingBox));
+        m_floats-&gt;remove(m_floats-&gt;find(&amp;floatingBox));
+    }
+
</ins><span class="cx">     Vector&lt;RenderBox*&gt;* floatsPtr() { ASSERT(!isDirty()); return m_floats.get(); }
</span><span class="cx"> 
</span><span class="cx">     virtual void extractLineBoxFromRenderObject() override final;
</span></span></pre>
</div>
</div>

</body>
</html>