[Webkit-unassigned] [Bug 166710] New: Crash inside Editor::styleForSelectionStart

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Wed Jan 4 19:15:59 PST 2017


https://bugs.webkit.org/show_bug.cgi?id=166710

            Bug ID: 166710
           Summary: Crash inside Editor::styleForSelectionStart
    Classification: Unclassified
           Product: WebKit
           Version: Safari 10
          Hardware: Unspecified
                OS: Unspecified
            Status: NEW
          Severity: Normal
          Priority: P2
         Component: HTML Editing
          Assignee: webkit-unassigned at lists.webkit.org
          Reporter: rniwa at webkit.org

0   com.apple.WebCore                 0x00007fffdbc6b2c4 WebCore::checkAcceptChild(WebCore::ContainerNode&, WebCore::Node&, WebCore::Node const*, WebCore::Document::AcceptChildOperation) + 36
1   com.apple.WebCore                 0x00007fffdbc6ceb7 WebCore::ContainerNode::appendChild(WebCore::Node&) + 39
2   com.apple.WebCore                 0x00007fffdbe26014 WebCore::Editor::styleForSelectionStart(WebCore::Frame*, WebCore::Node*&) + 628
3   com.apple.WebKit                  0x00007fffdd15bf98 WebKit::WebPage::editorState(WebKit::WebPage::IncludePostLayoutDataHint) const + 368
4   com.apple.WebKit                  0x00007fffdd15c357 WebKit::WebPage::updateEditorStateAfterLayoutIfEditabilityChanged() + 91
5   com.apple.WebCore                 0x00007fffdbeece3d WebCore::FrameSelection::updateAppearanceAfterLayout() + 45
6   com.apple.WebCore                 0x00007fffdb96aac1 WebCore::FrameView::performPostLayoutTasks() + 65
7   com.apple.WebCore                 0x00007fffdb9609b1 WebCore::FrameView::layout(bool) + 3969
8   com.apple.WebCore                 0x00007fffdb9c7f4b WebCore::Document::updateLayout() + 187
9   com.apple.WebCore                 0x00007fffdbdb1047 WebCore::Document::updateLayoutIgnorePendingStylesheets(WebCore::Document::RunPostLayoutTasks) + 295
10  com.apple.WebCore                 0x00007fffdb9f818d WebCore::Element::offsetTop() + 29
11  com.apple.WebCore                 0x00007fffdc21bff8 WebCore::jsElementOffsetTop(JSC::ExecState*, long long, JSC::PropertyName) + 72
12  com.apple.JavaScriptCore          0x00007fffd75eef90 JSC::getByVal(JSC::ExecState*, JSC::JSValue, JSC::JSValue, JSC::ByValInfo*, JSC::ReturnAddressPtr) + 5760

<rdar://problem/29763079>

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.webkit.org/pipermail/webkit-unassigned/attachments/20170105/d6c0c726/attachment-0001.html>


More information about the webkit-unassigned mailing list