[Webkit-unassigned] [Bug 81868] REGRESSION(r98542): crash when MatchedStyleDeclarationCache is resized

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Mon Apr 2 23:34:56 PDT 2012


https://bugs.webkit.org/show_bug.cgi?id=81868





--- Comment #1 from Mike Lawther <mikelawther at chromium.org>  2012-04-02 23:34:57 PST ---
The issue reported in http://code.google.com/p/chromium/issues/detail?id=103653 seems related - 

0x02851797     [chrome.dll     + 0x00c21797]    WebCore::DataRef<WebCore::SVGRenderStyle>::~DataRef<WebCore::SVGRenderStyle>()
0x0273cdf1     [chrome.dll     + 0x00b0cdf1]    WebCore::RenderStyle::`scalar deleting destructor'(unsigned int)
0x028c4273     [chrome.dll     - refptr.h:116    WTF::RefPtr<WebCore::RenderStyle>::operator=(WTF::RefPtr<WebCore::RenderStyle> const &)
0x028c3fc0     [chrome.dll     + 0x00c93fc0]    WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem::operator=(WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem const &)
0x028c446c     [chrome.dll     - hashtable.h:767    WTF::HashTable<unsigned int,std::pair<unsigned int,WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem>,WTF::PairFirstExtractor<std::pair<unsigned int,WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem> >,WTF::IntHash<unsigned int>,WTF::PairHashTraits<WTF::HashTraits<unsigned int>,WTF::HashTraits<WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem> >,WTF::HashTraits<unsigned int> >::reinsert(std::pair<unsigned int,WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem> &)
0x028c4110     [chrome.dll     - hashtable.h:909    WTF::HashTable<unsigned int,std::pair<unsigned int,WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem>,WTF::PairFirstExtractor<std::pair<unsigned int,WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem> >,WTF::IntHash<unsigned int>,WTF::PairHashTraits<WTF::HashTraits<unsigned int>,WTF::HashTraits<WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem> >,WTF::HashTraits<unsigned int> >::expand()
0x028c3e4c     [chrome.dll     - hashtable.h:701    WTF::HashTable<unsigned int,std::pair<unsigned int,WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem>,WTF::PairFirstExtractor<std::pair<unsigned int,WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem> >,WTF::IntHash<unsigned int>,WTF::PairHashTraits<WTF::HashTraits<unsigned int>,WTF::HashTraits<WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem> >,WTF::HashTraits<unsigned int> >::add<unsigned int,WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem,WTF::HashMapTranslator<std::pair<unsigned int,WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem>,WTF::PairHashTraits<WTF::HashTraits<unsigned int>,WTF::HashTraits<WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem> >,WTF::IntHash<unsigned int> > >(unsigned int const &,WebCore::CSSStyleSelector::MatchedStyleDeclarationCacheItem const &)
0x028bbba9     [chrome.dll     - cssstyleselector.cpp:2228    WebCore::CSSStyleSelector::addToMatchedDeclarationCache(WebCore::RenderStyle const *,unsigned int,WebCore::CSSStyleSelector::MatchResult const &)
0x028bbe22     [chrome.dll     - cssstyleselector.cpp:2300    WebCore::CSSStyleSelector::applyMatchedDeclarations(WebCore::CSSStyleSelector::MatchResult const &)
0x028b9d41     [chrome.dll     - cssstyleselector.cpp:1249    WebCore::CSSStyleSelector::styleForElement(WebCore::Element *,WebCore::RenderStyle *,bool,bool)

-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the webkit-unassigned mailing list