<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[195128] releases/WebKitGTK/webkit-2.10</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://trac.webkit.org/projects/webkit/changeset/195128">195128</a></dd>
<dt>Author</dt> <dd>carlosgc@webkit.org</dd>
<dt>Date</dt> <dd>2016-01-15 05:14:23 -0800 (Fri, 15 Jan 2016)</dd>
</dl>

<h3>Log Message</h3>
<pre>Merge <a href="http://trac.webkit.org/projects/webkit/changeset/194016">r194016</a> - Clean up absolute positioned map properly.
https://bugs.webkit.org/show_bug.cgi?id=152219
rdar://problem/23861165

Reviewed by Simon Fraser.

We insert positioned renderers into a static map (RenderBlock::gPositionedDescendantsMap) to keep track of them.
Since this static map is at block level, (positioned)inline renderers use their containing block to store
their positioned descendants.
This patch ensures that when an inline element can no longer hold positioned children, we remove them from
the inline's containing block's map. -unless the container itself can hold positioned renderers(see RenderElement::canContainAbsolutelyPositionedObjects).

Source/WebCore:

Test: fast/block/positioning/crash-when-positioned-inline-has-positioned-child.html

* rendering/RenderInline.cpp:
(WebCore::RenderInline::styleWillChange):
* rendering/RenderInline.h:

LayoutTests:

* fast/block/positioning/crash-when-positioned-inline-has-positioned-child-expected.txt: Added.
* fast/block/positioning/crash-when-positioned-inline-has-positioned-child.html: Added.</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#releasesWebKitGTKwebkit210LayoutTestsChangeLog">releases/WebKitGTK/webkit-2.10/LayoutTests/ChangeLog</a></li>
<li><a href="#releasesWebKitGTKwebkit210SourceWebCoreChangeLog">releases/WebKitGTK/webkit-2.10/Source/WebCore/ChangeLog</a></li>
<li><a href="#releasesWebKitGTKwebkit210SourceWebCorerenderingRenderInlinecpp">releases/WebKitGTK/webkit-2.10/Source/WebCore/rendering/RenderInline.cpp</a></li>
<li><a href="#releasesWebKitGTKwebkit210SourceWebCorerenderingRenderInlineh">releases/WebKitGTK/webkit-2.10/Source/WebCore/rendering/RenderInline.h</a></li>
</ul>

<h3>Added Paths</h3>
<ul>
<li><a href="#releasesWebKitGTKwebkit210LayoutTestsfastblockpositioningcrashwhenpositionedinlinehaspositionedchildexpectedtxt">releases/WebKitGTK/webkit-2.10/LayoutTests/fast/block/positioning/crash-when-positioned-inline-has-positioned-child-expected.txt</a></li>
<li><a href="#releasesWebKitGTKwebkit210LayoutTestsfastblockpositioningcrashwhenpositionedinlinehaspositionedchildhtml">releases/WebKitGTK/webkit-2.10/LayoutTests/fast/block/positioning/crash-when-positioned-inline-has-positioned-child.html</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="releasesWebKitGTKwebkit210LayoutTestsChangeLog"></a>
<div class="modfile"><h4>Modified: releases/WebKitGTK/webkit-2.10/LayoutTests/ChangeLog (195127 => 195128)</h4>
<pre class="diff"><span>
<span class="info">--- releases/WebKitGTK/webkit-2.10/LayoutTests/ChangeLog        2016-01-15 13:11:26 UTC (rev 195127)
+++ releases/WebKitGTK/webkit-2.10/LayoutTests/ChangeLog        2016-01-15 13:14:23 UTC (rev 195128)
</span><span class="lines">@@ -1,3 +1,20 @@
</span><ins>+2015-12-13  Zalan Bujtas  &lt;zalan@apple.com&gt;
+
+        Clean up absolute positioned map properly.
+        https://bugs.webkit.org/show_bug.cgi?id=152219
+        rdar://problem/23861165
+
+        Reviewed by Simon Fraser.
+
+        We insert positioned renderers into a static map (RenderBlock::gPositionedDescendantsMap) to keep track of them.
+        Since this static map is at block level, (positioned)inline renderers use their containing block to store
+        their positioned descendants.
+        This patch ensures that when an inline element can no longer hold positioned children, we remove them from
+        the inline's containing block's map. -unless the container itself can hold positioned renderers(see RenderElement::canContainAbsolutelyPositionedObjects).
+
+        * fast/block/positioning/crash-when-positioned-inline-has-positioned-child-expected.txt: Added.
+        * fast/block/positioning/crash-when-positioned-inline-has-positioned-child.html: Added.
+
</ins><span class="cx"> 2015-12-11  Zalan Bujtas  &lt;zalan@apple.com&gt;
</span><span class="cx"> 
</span><span class="cx">         ASSERTION FAILED: !rect.isEmpty() in WebCore::GraphicsContext::drawRect
</span></span></pre></div>
<a id="releasesWebKitGTKwebkit210LayoutTestsfastblockpositioningcrashwhenpositionedinlinehaspositionedchildexpectedtxt"></a>
<div class="addfile"><h4>Added: releases/WebKitGTK/webkit-2.10/LayoutTests/fast/block/positioning/crash-when-positioned-inline-has-positioned-child-expected.txt (0 => 195128)</h4>
<pre class="diff"><span>
<span class="info">--- releases/WebKitGTK/webkit-2.10/LayoutTests/fast/block/positioning/crash-when-positioned-inline-has-positioned-child-expected.txt                                (rev 0)
+++ releases/WebKitGTK/webkit-2.10/LayoutTests/fast/block/positioning/crash-when-positioned-inline-has-positioned-child-expected.txt        2016-01-15 13:14:23 UTC (rev 195128)
</span><span class="lines">@@ -0,0 +1 @@
</span><ins>+Pass if no assert in debug.
</ins></span></pre></div>
<a id="releasesWebKitGTKwebkit210LayoutTestsfastblockpositioningcrashwhenpositionedinlinehaspositionedchildhtml"></a>
<div class="addfile"><h4>Added: releases/WebKitGTK/webkit-2.10/LayoutTests/fast/block/positioning/crash-when-positioned-inline-has-positioned-child.html (0 => 195128)</h4>
<pre class="diff"><span>
<span class="info">--- releases/WebKitGTK/webkit-2.10/LayoutTests/fast/block/positioning/crash-when-positioned-inline-has-positioned-child.html                                (rev 0)
+++ releases/WebKitGTK/webkit-2.10/LayoutTests/fast/block/positioning/crash-when-positioned-inline-has-positioned-child.html        2016-01-15 13:14:23 UTC (rev 195128)
</span><span class="lines">@@ -0,0 +1,16 @@
</span><ins>+Pass if no assert in debug.
+&lt;div id=wrapper&gt;&lt;span id=container style=&quot;position: relative;&quot;&gt;&lt;span style=&quot;position: absolute;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;div&gt;
+&lt;script&gt;
+if (window.testRunner)
+    testRunner.dumpAsText();
+document.getElementById(&quot;container&quot;).innerText;
+document.getElementById(&quot;container&quot;).setAttribute(&quot;style&quot;,&quot;-webkit-justify-self: stretch;&quot;);
+if (window.testRunner)
+    testRunner.waitUntilDone();
+setTimeout(function() { 
+ var element = document.getElementById(&quot;wrapper&quot;);
+ element.parentNode.removeChild(element);
+  if (window.testRunner)
+      testRunner.notifyDone();
+  }, 0);
+&lt;/script&gt;
</ins></span></pre></div>
<a id="releasesWebKitGTKwebkit210SourceWebCoreChangeLog"></a>
<div class="modfile"><h4>Modified: releases/WebKitGTK/webkit-2.10/Source/WebCore/ChangeLog (195127 => 195128)</h4>
<pre class="diff"><span>
<span class="info">--- releases/WebKitGTK/webkit-2.10/Source/WebCore/ChangeLog        2016-01-15 13:11:26 UTC (rev 195127)
+++ releases/WebKitGTK/webkit-2.10/Source/WebCore/ChangeLog        2016-01-15 13:14:23 UTC (rev 195128)
</span><span class="lines">@@ -1,3 +1,23 @@
</span><ins>+2015-12-13  Zalan Bujtas  &lt;zalan@apple.com&gt;
+
+        Clean up absolute positioned map properly.
+        https://bugs.webkit.org/show_bug.cgi?id=152219
+        rdar://problem/23861165
+
+        Reviewed by Simon Fraser.
+
+        We insert positioned renderers into a static map (RenderBlock::gPositionedDescendantsMap) to keep track of them.
+        Since this static map is at block level, (positioned)inline renderers use their containing block to store
+        their positioned descendants.
+        This patch ensures that when an inline element can no longer hold positioned children, we remove them from
+        the inline's containing block's map. -unless the container itself can hold positioned renderers(see RenderElement::canContainAbsolutelyPositionedObjects).
+
+        Test: fast/block/positioning/crash-when-positioned-inline-has-positioned-child.html
+
+        * rendering/RenderInline.cpp:
+        (WebCore::RenderInline::styleWillChange):
+        * rendering/RenderInline.h:
+
</ins><span class="cx"> 2015-12-11  Zalan Bujtas  &lt;zalan@apple.com&gt;
</span><span class="cx"> 
</span><span class="cx">         ASSERTION FAILED: !rect.isEmpty() in WebCore::GraphicsContext::drawRect
</span></span></pre></div>
<a id="releasesWebKitGTKwebkit210SourceWebCorerenderingRenderInlinecpp"></a>
<div class="modfile"><h4>Modified: releases/WebKitGTK/webkit-2.10/Source/WebCore/rendering/RenderInline.cpp (195127 => 195128)</h4>
<pre class="diff"><span>
<span class="info">--- releases/WebKitGTK/webkit-2.10/Source/WebCore/rendering/RenderInline.cpp        2016-01-15 13:11:26 UTC (rev 195127)
+++ releases/WebKitGTK/webkit-2.10/Source/WebCore/rendering/RenderInline.cpp        2016-01-15 13:14:23 UTC (rev 195128)
</span><span class="lines">@@ -164,6 +164,19 @@
</span><span class="cx">     }
</span><span class="cx"> }
</span><span class="cx"> 
</span><ins>+void RenderInline::styleWillChange(StyleDifference diff, const RenderStyle&amp; newStyle)
+{
+    RenderBoxModelObject::styleWillChange(diff, newStyle);
+
+    // Check if this inline can hold absolute positioned elmements even after the style change.
+    if (canContainAbsolutelyPositionedObjects() &amp;&amp; newStyle.position() == StaticPosition) {
+        // RenderInlines forward their absolute positioned descendants to their (non-anonymous) containing block.
+        auto* container = containingBlockForAbsolutePosition();
+        if (container &amp;&amp; !container-&gt;canContainAbsolutelyPositionedObjects())
+            container-&gt;removePositionedObjects(nullptr, NewContainingBlock);
+    }
+}
+
</ins><span class="cx"> void RenderInline::styleDidChange(StyleDifference diff, const RenderStyle* oldStyle)
</span><span class="cx"> {
</span><span class="cx">     RenderBoxModelObject::styleDidChange(diff, oldStyle);
</span></span></pre></div>
<a id="releasesWebKitGTKwebkit210SourceWebCorerenderingRenderInlineh"></a>
<div class="modfile"><h4>Modified: releases/WebKitGTK/webkit-2.10/Source/WebCore/rendering/RenderInline.h (195127 => 195128)</h4>
<pre class="diff"><span>
<span class="info">--- releases/WebKitGTK/webkit-2.10/Source/WebCore/rendering/RenderInline.h        2016-01-15 13:11:26 UTC (rev 195127)
+++ releases/WebKitGTK/webkit-2.10/Source/WebCore/rendering/RenderInline.h        2016-01-15 13:14:23 UTC (rev 195128)
</span><span class="lines">@@ -104,6 +104,7 @@
</span><span class="cx"> protected:
</span><span class="cx">     virtual void willBeDestroyed() override;
</span><span class="cx"> 
</span><ins>+    void styleWillChange(StyleDifference, const RenderStyle&amp; newStyle) override;
</ins><span class="cx">     virtual void styleDidChange(StyleDifference, const RenderStyle* oldStyle) override;
</span><span class="cx"> 
</span><span class="cx">     virtual void updateFromStyle() override;
</span></span></pre>
</div>
</div>

</body>
</html>