Changeset 254559 in webkit
- Timestamp:
- Jan 14, 2020, 10:32:01 PM (7 years ago)
- Location:
- trunk
- Files:
-
- 2 added
- 8 edited
-
LayoutTests/ChangeLog (modified) (1 diff)
-
LayoutTests/fast/inline/long-continuation-crash-expected.txt (added)
-
LayoutTests/fast/inline/long-continuation-crash.html (added)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/rendering/RenderBlock.cpp (modified) (1 diff)
-
Source/WebCore/rendering/RenderBlock.h (modified) (1 diff)
-
Source/WebCore/rendering/RenderBoxModelObject.cpp (modified) (1 diff)
-
Source/WebCore/rendering/RenderBoxModelObject.h (modified) (1 diff)
-
Source/WebCore/rendering/RenderInline.cpp (modified) (1 diff)
-
Source/WebCore/rendering/RenderInline.h (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
trunk/LayoutTests/ChangeLog
r254555 r254559 1 2020-01-14 Zalan Bujtas <zalan@apple.com> 2 3 Long continuation chain could lead to stack exhaustion 4 https://bugs.webkit.org/show_bug.cgi?id=206271 5 <rdar://problem/41189798> 6 7 Reviewed by Simon Fraser. 8 9 * fast/inline/long-continuation-crash.html: Added. 10 1 11 2020-01-14 Peng Liu <peng.liu6@apple.com> 2 12 -
trunk/Source/WebCore/ChangeLog
r254557 r254559 1 2020-01-14 Zalan Bujtas <zalan@apple.com> 2 3 Long continuation chain could lead to stack exhaustion 4 https://bugs.webkit.org/show_bug.cgi?id=206271 5 <rdar://problem/41189798> 6 7 Reviewed by Simon Fraser. 8 9 This patch replaces the recursive approach with an iterative one 10 to collect absolute quads across continuation. 11 12 Test: fast/inline/long-continuation-crash.html 13 14 * rendering/RenderBlock.cpp: 15 (WebCore::RenderBlock::absoluteQuads const): 16 (WebCore::RenderBlock::absoluteQuadsIgnoringContinuation const): 17 * rendering/RenderBlock.h: 18 * rendering/RenderBoxModelObject.cpp: 19 (WebCore::RenderBoxModelObject::collectAbsoluteQuadsForContinuation const): 20 * rendering/RenderBoxModelObject.h: 21 (WebCore::RenderBoxModelObject::absoluteQuadsIgnoringContinuation const): 22 * rendering/RenderInline.cpp: 23 (WebCore::RenderInline::absoluteQuads const): 24 (WebCore::RenderInline::absoluteQuadsIgnoringContinuation const): 25 * rendering/RenderInline.h: 26 1 27 2020-01-14 Ryosuke Niwa <rniwa@webkit.org> 2 28 -
trunk/Source/WebCore/rendering/RenderBlock.cpp
r254421 r254559 2782 2782 void RenderBlock::absoluteQuads(Vector<FloatQuad>& quads, bool* wasFixed) const 2783 2783 { 2784 if (!continuation()) { 2785 absoluteQuadsIgnoringContinuation({ { }, size() }, quads, wasFixed); 2786 return; 2787 } 2784 2788 // For blocks inside inlines, we include margins so that we run right up to the inline boxes 2785 2789 // above and below us (thus getting merged with them to form a single irregular shape). 2786 auto* continuation = this->continuation(); 2787 FloatRect localRect = continuation 2788 ? FloatRect(0, -collapsedMarginBefore(), width(), height() + collapsedMarginBefore() + collapsedMarginAfter()) 2789 : FloatRect(0, 0, width(), height()); 2790 2790 auto logicalRect = FloatRect { 0, -collapsedMarginBefore(), width(), height() + collapsedMarginBefore() + collapsedMarginAfter() }; 2791 absoluteQuadsIgnoringContinuation(logicalRect, quads, wasFixed); 2792 collectAbsoluteQuadsForContinuation(quads, wasFixed); 2793 } 2794 2795 void RenderBlock::absoluteQuadsIgnoringContinuation(const FloatRect& logicalRect, Vector<FloatQuad>& quads, bool* wasFixed) const 2796 { 2791 2797 // FIXME: This is wrong for block-flows that are horizontal. 2792 2798 // https://bugs.webkit.org/show_bug.cgi?id=46781 2793 RenderFragmentedFlow* fragmentedFlow = enclosingFragmentedFlow(); 2794 if (!fragmentedFlow || !fragmentedFlow->absoluteQuadsForBox(quads, wasFixed, this, localRect.y(), localRect.maxY())) 2795 quads.append(localToAbsoluteQuad(localRect, UseTransforms, wasFixed)); 2796 2797 if (continuation) 2798 continuation->absoluteQuads(quads, wasFixed); 2799 auto* fragmentedFlow = enclosingFragmentedFlow(); 2800 if (!fragmentedFlow || !fragmentedFlow->absoluteQuadsForBox(quads, wasFixed, this, logicalRect.y(), logicalRect.maxY())) 2801 quads.append(localToAbsoluteQuad(logicalRect, UseTransforms, wasFixed)); 2799 2802 } 2800 2803 -
trunk/Source/WebCore/rendering/RenderBlock.h
r254087 r254559 494 494 void removePositionedObjectsIfNeeded(const RenderStyle& oldStyle, const RenderStyle& newStyle); 495 495 496 void absoluteQuadsIgnoringContinuation(const FloatRect&, Vector<FloatQuad>&, bool* wasFixed) const override; 497 496 498 private: 497 499 bool hasRareData() const; -
trunk/Source/WebCore/rendering/RenderBoxModelObject.cpp
r254087 r254559 2696 2696 } 2697 2697 2698 void RenderBoxModelObject::collectAbsoluteQuadsForContinuation(Vector<FloatQuad>& quads, bool* wasFixed) const 2699 { 2700 ASSERT(continuation()); 2701 for (auto* nextInContinuation = this->continuation(); nextInContinuation; nextInContinuation = nextInContinuation->continuation()) { 2702 if (is<RenderBlock>(*nextInContinuation)) { 2703 auto& blockBox = downcast<RenderBlock>(*nextInContinuation); 2704 // For blocks inside inlines, we include margins so that we run right up to the inline boxes 2705 // above and below us (thus getting merged with them to form a single irregular shape). 2706 auto logicalRect = FloatRect { 0, -blockBox.collapsedMarginBefore(), blockBox.width(), 2707 blockBox.height() + blockBox.collapsedMarginBefore() + blockBox.collapsedMarginAfter() }; 2708 nextInContinuation->absoluteQuadsIgnoringContinuation(logicalRect, quads, wasFixed); 2709 continue; 2710 } 2711 nextInContinuation->absoluteQuadsIgnoringContinuation({ }, quads, wasFixed); 2712 } 2713 } 2714 2698 2715 } // namespace WebCore -
trunk/Source/WebCore/rendering/RenderBoxModelObject.h
r252965 r254559 295 295 protected: 296 296 LayoutUnit computedCSSPadding(const Length&) const; 297 virtual void absoluteQuadsIgnoringContinuation(const FloatRect&, Vector<FloatQuad>&, bool* /*wasFixed*/) const { ASSERT_NOT_REACHED(); } 298 void collectAbsoluteQuadsForContinuation(Vector<FloatQuad>& quads, bool* wasFixed) const; 297 299 298 300 private: -
trunk/Source/WebCore/rendering/RenderInline.cpp
r254087 r254559 413 413 void RenderInline::absoluteQuads(Vector<FloatQuad>& quads, bool* wasFixed) const 414 414 { 415 absoluteQuadsIgnoringContinuation({ }, quads, wasFixed); 416 if (continuation()) 417 collectAbsoluteQuadsForContinuation(quads, wasFixed); 418 } 419 420 void RenderInline::absoluteQuadsIgnoringContinuation(const FloatRect&, Vector<FloatQuad>& quads, bool*) const 421 { 415 422 AbsoluteQuadsGeneratorContext context(this, quads); 416 423 generateLineBoxRects(context); 417 418 if (RenderBoxModelObject* continuation = this->continuation())419 continuation->absoluteQuads(quads, wasFixed);420 424 } 421 425 -
trunk/Source/WebCore/rendering/RenderInline.h
r246285 r254559 110 110 InlineBox* culledInlineLastLineBox() const; 111 111 112 void absoluteQuadsIgnoringContinuation(const FloatRect&, Vector<FloatQuad>&, bool* wasFixed) const override; 113 112 114 template<typename GeneratorContext> 113 115 void generateLineBoxRects(GeneratorContext& yield) const;
Note:
See TracChangeset
for help on using the changeset viewer.