[Webkit-unassigned] [Bug 23704] New: Safari crashes on getComputedTextLength

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Tue Feb 3 01:52:57 PST 2009


https://bugs.webkit.org/show_bug.cgi?id=23704

           Summary: Safari crashes on getComputedTextLength
           Product: WebKit
           Version: 525.x (Safari 3.2)
          Platform: Macintosh
               URL: http://rapidrabb.it/files/safari-crash.xhtml
        OS/Version: Mac OS X 10.4
            Status: UNCONFIRMED
          Severity: Normal
          Priority: P2
         Component: SVG
        AssignedTo: webkit-unassigned at lists.webkit.org
        ReportedBy: volker at rapidrabb.it


Have a look at the <a
href="http://rapidrabb.it/files/safari-crash.xhtml">sample</a>. Pressing the
button in Safari 3.2.1 (and probably back to some 3.1 version of Safari) causes
the whole browser to crash. See the error report below. 

Note: this sample works fine with the nightly of webkit. => would be nice if
the fix gets into the next Safari version.



Date/Time:      2009-02-03 10:50:19.661 +0100
OS Version:     10.4.11 (Build 8S2167)
Report Version: 4

Command: Safari
Path:    /Applications/Safari.app/Contents/MacOS/Safari
Parent:  WindowServer [77]

Version:        3.2.1 (4525.27.1)
Build Version:  1
Project Name:   WebBrowser
Source Version: 45252701

PID:    19970
Thread: 0

Exception:  EXC_BAD_ACCESS (0x0001)
Codes:      KERN_PROTECTION_FAILURE (0x0002) at 0x0000001a

Thread 0 Crashed:
0   com.apple.WebCore           0x013519e5
WebCore::findInlineTextBoxInTextChunks(WebCore::SVGTextContentElement const*,
WTF::Vector<WebCore::SVGTextChunk, (unsigned long)0> const&) + 127
1   com.apple.WebCore           0x01375925
WebCore::SVGTextContentElement::getComputedTextLength() const + 245
2   com.apple.WebCore           0x013757bd
WebCore::jsSVGTextContentElementPrototypeFunctionGetComputedTextLength(KJS::ExecState*,
KJS::JSObject*, KJS::List const&) + 71


-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.



More information about the webkit-unassigned mailing list