<html>
<head>
<base href="https://bugs.webkit.org/" />
</head>
<body><table border="1" cellspacing="0" cellpadding="8">
<tr>
<th>Bug ID</th>
<td><a class="bz_bug_link
bz_status_NEW "
title="NEW - Crash inside Editor::styleForSelectionStart"
href="https://bugs.webkit.org/show_bug.cgi?id=166710">166710</a>
</td>
</tr>
<tr>
<th>Summary</th>
<td>Crash inside Editor::styleForSelectionStart
</td>
</tr>
<tr>
<th>Classification</th>
<td>Unclassified
</td>
</tr>
<tr>
<th>Product</th>
<td>WebKit
</td>
</tr>
<tr>
<th>Version</th>
<td>Safari 10
</td>
</tr>
<tr>
<th>Hardware</th>
<td>Unspecified
</td>
</tr>
<tr>
<th>OS</th>
<td>Unspecified
</td>
</tr>
<tr>
<th>Status</th>
<td>NEW
</td>
</tr>
<tr>
<th>Severity</th>
<td>Normal
</td>
</tr>
<tr>
<th>Priority</th>
<td>P2
</td>
</tr>
<tr>
<th>Component</th>
<td>HTML Editing
</td>
</tr>
<tr>
<th>Assignee</th>
<td>webkit-unassigned@lists.webkit.org
</td>
</tr>
<tr>
<th>Reporter</th>
<td>rniwa@webkit.org
</td>
</tr></table>
<p>
<div>
<pre>0 com.apple.WebCore 0x00007fffdbc6b2c4 WebCore::checkAcceptChild(WebCore::ContainerNode&, WebCore::Node&, WebCore::Node const*, WebCore::Document::AcceptChildOperation) + 36
1 com.apple.WebCore 0x00007fffdbc6ceb7 WebCore::ContainerNode::appendChild(WebCore::Node&) + 39
2 com.apple.WebCore 0x00007fffdbe26014 WebCore::Editor::styleForSelectionStart(WebCore::Frame*, WebCore::Node*&) + 628
3 com.apple.WebKit 0x00007fffdd15bf98 WebKit::WebPage::editorState(WebKit::WebPage::IncludePostLayoutDataHint) const + 368
4 com.apple.WebKit 0x00007fffdd15c357 WebKit::WebPage::updateEditorStateAfterLayoutIfEditabilityChanged() + 91
5 com.apple.WebCore 0x00007fffdbeece3d WebCore::FrameSelection::updateAppearanceAfterLayout() + 45
6 com.apple.WebCore 0x00007fffdb96aac1 WebCore::FrameView::performPostLayoutTasks() + 65
7 com.apple.WebCore 0x00007fffdb9609b1 WebCore::FrameView::layout(bool) + 3969
8 com.apple.WebCore 0x00007fffdb9c7f4b WebCore::Document::updateLayout() + 187
9 com.apple.WebCore 0x00007fffdbdb1047 WebCore::Document::updateLayoutIgnorePendingStylesheets(WebCore::Document::RunPostLayoutTasks) + 295
10 com.apple.WebCore 0x00007fffdb9f818d WebCore::Element::offsetTop() + 29
11 com.apple.WebCore 0x00007fffdc21bff8 WebCore::jsElementOffsetTop(JSC::ExecState*, long long, JSC::PropertyName) + 72
12 com.apple.JavaScriptCore 0x00007fffd75eef90 JSC::getByVal(JSC::ExecState*, JSC::JSValue, JSC::JSValue, JSC::ByValInfo*, JSC::ReturnAddressPtr) + 5760
<rdar://problem/29763079></pre>
</div>
</p>
<hr>
<span>You are receiving this mail because:</span>
<ul>
<li>You are the assignee for the bug.</li>
</ul>
</body>
</html>