[Webkit-unassigned] [Bug 178332] Text nodes with display:contents parent should render as if they were wrapped in an unstyled <span>

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Tue Oct 17 02:12:50 PDT 2017


Ryosuke Niwa <rniwa at webkit.org> changed:

           What    |Removed                     |Added
                 CC|                            |rniwa at webkit.org
 Attachment #324001|review?                     |review+
              Flags|                            |

--- Comment #11 from Ryosuke Niwa <rniwa at webkit.org> ---
Comment on attachment 324001
  --> https://bugs.webkit.org/attachment.cgi?id=324001

View in context: https://bugs.webkit.org/attachment.cgi?id=324001&action=review

> Source/WebCore/rendering/RenderElement.cpp:228
> +        auto* textRendererWithDisplayContentsParent = RenderText::findForDisplayContentsInlineWrapper(rendererForFirstLineStyle);

Maybe we call this findByDisplayContentsInlineWrapperCandidate instead?

> Source/WebCore/rendering/RenderText.cpp:137
> +    static NeverDestroyed<HashMap<const RenderText*, WeakPtr<RenderInline>>> map;

It would be nice if we can make it so that nobody can possibly de-reference RenderText* so that it's UAF-safe
but that'd require quite a bit of hash traits hackery... :(

> Source/WebCore/rendering/RenderText.cpp:1761
> +        inlineWrapperForDisplayContentsMap().remove(this);

Can we assert that the entry did exist in the map?

> Source/WebCore/rendering/RenderText.cpp:1765
> +    inlineWrapperForDisplayContentsMap().add(this, makeWeakPtr(wrapper));

Can we assert that this is isNewEntry?

> LayoutTests/ChangeLog:10
> +2017-10-16  Antti Koivisto  <antti at apple.com>

Double change log entries.

You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20171017/114d25c6/attachment-0001.html>

More information about the webkit-unassigned mailing list