⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 130719 in webkit


Ignore:
Timestamp:
Oct 8, 2012, 10:31:47 PM (14 years ago)
Author:
yosin@chromium.org
Message:

Merge 130717 - HTMLSelectElement::typeAheadFind depends on implementation dependent behavior
​https://bugs.webkit.org/show_bug.cgi?id=98710

Reviewed by Kent Tamura.

Source/WebCore:

This patch gets rid of C/C++ implementation dependent behavior from
HTMLSelectElement::typeAheadFind() which does modulo operation with
a negative operand.

HTMLSelectElement::typeAheadFind() contains expression with modulo
operator and dividend can be -1 when the "select" element without
"option" element but "optgroup" element.

Test: fast/forms/select/select-typeahead-crash.html

  • html/HTMLSelectElement.cpp:

(WebCore::HTMLSelectElement::typeAheadFind): Changed to do modulo
operation with both operands are non-negative.

LayoutTests:

This patch adds a test for checking HTMLSelectElement::typeAheadFind
doesn't crash.

  • fast/forms/select/select-typeahead-crash-expected.txt: Added.
  • fast/forms/select/select-typeahead-crash.html: Added.

TBR=​yosin@chromium.org
Review URL: ​https://codereview.chromium.org/11091018

Location:
branches/chromium/1229
Files:
1 edited
2 copied

Legend:

Unmodified
Added
Removed
  • branches/chromium/1229/Source/WebCore/html/HTMLSelectElement.cpp

    r124416 r130719  
    15151515
    15161516    int selected = selectedIndex();
    1517     int index = (optionToListIndex(selected >= 0 ? selected : 0) + searchStartOffset) % itemCount;
    1518     ASSERT(index >= 0);
     1517    int index = optionToListIndex(selected >= 0 ? selected : 0) + searchStartOffset;
     1518    if (index < 0)
     1519        return;
     1520    index %= itemCount;
    15191521
    15201522    // Compute a case-folded copy of the prefix string before beginning the search for
Note: See TracChangeset for help on using the changeset viewer.