<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>193996</bug_id>
          
          <creation_ts>2019-01-29 16:37:09 -0800</creation_ts>
          <short_desc>iOS: Nullptr crash in WebPage::getPositionInformation dereferencing an input element for data list</short_desc>
          <delta_ts>2019-01-29 18:55:05 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ryosuke Niwa">rniwa</reporter>
          <assigned_to name="Ryosuke Niwa">rniwa</assigned_to>
          <cc>cdumez</cc>
    
    <cc>commit-queue</cc>
    
    <cc>ddkilzer</cc>
    
    <cc>wenson_hsieh</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1499804</commentid>
    <comment_count>0</comment_count>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2019-01-29 16:37:09 -0800</bug_when>
    <thetext>We&apos;re crashing in the middle in the following code because hitNode can be nullptr here.

#if ENABLE(DATALIST_ELEMENT)
    if (is&lt;HTMLInputElement&gt;(*hitNode)) {
        const HTMLInputElement&amp; input = downcast&lt;HTMLInputElement&gt;(*hitNode);
        if (input.list()) {
            HitTestResult result = m_page-&gt;mainFrame().eventHandler().hitTestResultAtPoint(request.point, HitTestRequest::ReadOnly | HitTestRequest::Active);
            if (result.innerNode() == input.dataListButtonElement())
                info.preventTextInteraction = true;
        }
    }
#endif

&lt;rdar://problem/31247273&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1499805</commentid>
    <comment_count>1</comment_count>
      <attachid>360524</attachid>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2019-01-29 16:38:08 -0800</bug_when>
    <thetext>Created attachment 360524
Fixes the bug</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1499806</commentid>
    <comment_count>2</comment_count>
      <attachid>360524</attachid>
    <who name="Wenson Hsieh">wenson_hsieh</who>
    <bug_when>2019-01-29 16:39:07 -0800</bug_when>
    <thetext>Comment on attachment 360524
Fixes the bug

View in context: https://bugs.webkit.org/attachment.cgi?id=360524&amp;action=review

&gt; Source/WebKit/WebProcess/WebPage/ios/WebPageIOS.mm:2251
&gt; +    if (hitNode &amp;&amp; is&lt;HTMLInputElement&gt;(*hitNode)) {

Let&apos;s just check is&lt;HTMLInputElement&gt;(hitNode).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1499807</commentid>
    <comment_count>3</comment_count>
      <attachid>360525</attachid>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2019-01-29 16:39:41 -0800</bug_when>
    <thetext>Created attachment 360525
Patch for landing</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1499808</commentid>
    <comment_count>4</comment_count>
      <attachid>360525</attachid>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2019-01-29 16:40:00 -0800</bug_when>
    <thetext>Comment on attachment 360525
Patch for landing

Wait for EWS.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1499853</commentid>
    <comment_count>5</comment_count>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2019-01-29 18:55:05 -0800</bug_when>
    <thetext>Committed r240702: &lt;https://trac.webkit.org/changeset/240702&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>360524</attachid>
            <date>2019-01-29 16:38:08 -0800</date>
            <delta_ts>2019-01-29 16:39:39 -0800</delta_ts>
            <desc>Fixes the bug</desc>
            <filename>bug-193996-20190129163807.patch</filename>
            <type>text/plain</type>
            <size>1522</size>
            <attacher name="Ryosuke Niwa">rniwa</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XZWJL
aXQvQ2hhbmdlTG9nCShyZXZpc2lvbiAyNDA2OTEpCisrKyBTb3VyY2UvV2ViS2l0L0NoYW5nZUxv
Zwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE1IEBACisyMDE5LTAxLTI5ICBSeW9zdWtlIE5p
d2EgIDxybml3YUB3ZWJraXQub3JnPgorCisgICAgICAgIGlPUzogTnVsbHB0ciBjcmFzaCBpbiBX
ZWJQYWdlOjpnZXRQb3NpdGlvbkluZm9ybWF0aW9uIGRlcmVmZXJlbmNpbmcgYW4gaW5wdXQgZWxl
bWVudCBmb3IgZGF0YSBsaXN0CisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3df
YnVnLmNnaT9pZD0xOTM5OTYKKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4K
KworICAgICAgICBBZGRlZCBhIG1pc3NpbmcgbnVsbHB0ciBjaGVjay4KKworICAgICAgICAqIFdl
YlByb2Nlc3MvV2ViUGFnZS9pb3MvV2ViUGFnZUlPUy5tbToKKyAgICAgICAgKFdlYktpdDo6V2Vi
UGFnZTo6Z2V0UG9zaXRpb25JbmZvcm1hdGlvbik6CisKIDIwMTktMDEtMjkgIFlvdWVubiBGYWJs
ZXQgIDx5b3Vlbm5AYXBwbGUuY29tPgogCiAgICAgICAgIEFkb3B0IG5ldyBTUEkgdG8gZXZhbHVh
dGUgc2VydmVyIGNlcnRpZmljYXRlIHRydXN0CkluZGV4OiBTb3VyY2UvV2ViS2l0L1dlYlByb2Nl
c3MvV2ViUGFnZS9pb3MvV2ViUGFnZUlPUy5tbQo9PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2ViS2l0
L1dlYlByb2Nlc3MvV2ViUGFnZS9pb3MvV2ViUGFnZUlPUy5tbQkocmV2aXNpb24gMjQwNjQ2KQor
KysgU291cmNlL1dlYktpdC9XZWJQcm9jZXNzL1dlYlBhZ2UvaW9zL1dlYlBhZ2VJT1MubW0JKHdv
cmtpbmcgY29weSkKQEAgLTIyNDgsNyArMjI0OCw3IEBAIHZvaWQgV2ViUGFnZTo6Z2V0UG9zaXRp
b25JbmZvcm1hdGlvbihjb24KIAogICAgIC8vIFByZXZlbnQgdGhlIGNhbGxvdXQgYmFyIGZyb20g
c2hvd2luZyB3aGVuIHRhcHBpbmcgb24gdGhlIGRhdGFsaXN0IGJ1dHRvbi4KICNpZiBFTkFCTEUo
REFUQUxJU1RfRUxFTUVOVCkKLSAgICBpZiAoaXM8SFRNTElucHV0RWxlbWVudD4oKmhpdE5vZGUp
KSB7CisgICAgaWYgKGhpdE5vZGUgJiYgaXM8SFRNTElucHV0RWxlbWVudD4oKmhpdE5vZGUpKSB7
CiAgICAgICAgIGNvbnN0IEhUTUxJbnB1dEVsZW1lbnQmIGlucHV0ID0gZG93bmNhc3Q8SFRNTElu
cHV0RWxlbWVudD4oKmhpdE5vZGUpOwogICAgICAgICBpZiAoaW5wdXQubGlzdCgpKSB7CiAgICAg
ICAgICAgICBIaXRUZXN0UmVzdWx0IHJlc3VsdCA9IG1fcGFnZS0+bWFpbkZyYW1lKCkuZXZlbnRI
YW5kbGVyKCkuaGl0VGVzdFJlc3VsdEF0UG9pbnQocmVxdWVzdC5wb2ludCwgSGl0VGVzdFJlcXVl
c3Q6OlJlYWRPbmx5IHwgSGl0VGVzdFJlcXVlc3Q6OkFjdGl2ZSk7Cg==
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>360525</attachid>
            <date>2019-01-29 16:39:41 -0800</date>
            <delta_ts>2019-01-29 16:40:00 -0800</delta_ts>
            <desc>Patch for landing</desc>
            <filename>bug-193996-20190129163940.patch</filename>
            <type>text/plain</type>
            <size>1508</size>
            <attacher name="Ryosuke Niwa">rniwa</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XZWJL
aXQvQ2hhbmdlTG9nCShyZXZpc2lvbiAyNDA2OTEpCisrKyBTb3VyY2UvV2ViS2l0L0NoYW5nZUxv
Zwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE1IEBACisyMDE5LTAxLTI5ICBSeW9zdWtlIE5p
d2EgIDxybml3YUB3ZWJraXQub3JnPgorCisgICAgICAgIGlPUzogTnVsbHB0ciBjcmFzaCBpbiBX
ZWJQYWdlOjpnZXRQb3NpdGlvbkluZm9ybWF0aW9uIGRlcmVmZXJlbmNpbmcgYW4gaW5wdXQgZWxl
bWVudCBmb3IgZGF0YSBsaXN0CisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3df
YnVnLmNnaT9pZD0xOTM5OTYKKworICAgICAgICBSZXZpZXdlZCBieSBXZW5zb24gSHNpZWguCisK
KyAgICAgICAgQWRkZWQgYSBtaXNzaW5nIG51bGxwdHIgY2hlY2suCisKKyAgICAgICAgKiBXZWJQ
cm9jZXNzL1dlYlBhZ2UvaW9zL1dlYlBhZ2VJT1MubW06CisgICAgICAgIChXZWJLaXQ6OldlYlBh
Z2U6OmdldFBvc2l0aW9uSW5mb3JtYXRpb24pOgorCiAyMDE5LTAxLTI5ICBZb3Vlbm4gRmFibGV0
ICA8eW91ZW5uQGFwcGxlLmNvbT4KIAogICAgICAgICBBZG9wdCBuZXcgU1BJIHRvIGV2YWx1YXRl
IHNlcnZlciBjZXJ0aWZpY2F0ZSB0cnVzdApJbmRleDogU291cmNlL1dlYktpdC9XZWJQcm9jZXNz
L1dlYlBhZ2UvaW9zL1dlYlBhZ2VJT1MubW0KPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291cmNlL1dlYktpdC9X
ZWJQcm9jZXNzL1dlYlBhZ2UvaW9zL1dlYlBhZ2VJT1MubW0JKHJldmlzaW9uIDI0MDY0NikKKysr
IFNvdXJjZS9XZWJLaXQvV2ViUHJvY2Vzcy9XZWJQYWdlL2lvcy9XZWJQYWdlSU9TLm1tCSh3b3Jr
aW5nIGNvcHkpCkBAIC0yMjQ4LDcgKzIyNDgsNyBAQCB2b2lkIFdlYlBhZ2U6OmdldFBvc2l0aW9u
SW5mb3JtYXRpb24oY29uCiAKICAgICAvLyBQcmV2ZW50IHRoZSBjYWxsb3V0IGJhciBmcm9tIHNo
b3dpbmcgd2hlbiB0YXBwaW5nIG9uIHRoZSBkYXRhbGlzdCBidXR0b24uCiAjaWYgRU5BQkxFKERB
VEFMSVNUX0VMRU1FTlQpCi0gICAgaWYgKGlzPEhUTUxJbnB1dEVsZW1lbnQ+KCpoaXROb2RlKSkg
eworICAgIGlmIChpczxIVE1MSW5wdXRFbGVtZW50PihoaXROb2RlKSkgewogICAgICAgICBjb25z
dCBIVE1MSW5wdXRFbGVtZW50JiBpbnB1dCA9IGRvd25jYXN0PEhUTUxJbnB1dEVsZW1lbnQ+KCpo
aXROb2RlKTsKICAgICAgICAgaWYgKGlucHV0Lmxpc3QoKSkgewogICAgICAgICAgICAgSGl0VGVz
dFJlc3VsdCByZXN1bHQgPSBtX3BhZ2UtPm1haW5GcmFtZSgpLmV2ZW50SGFuZGxlcigpLmhpdFRl
c3RSZXN1bHRBdFBvaW50KHJlcXVlc3QucG9pbnQsIEhpdFRlc3RSZXF1ZXN0OjpSZWFkT25seSB8
IEhpdFRlc3RSZXF1ZXN0OjpBY3RpdmUpOwo=
</data>

          </attachment>
      

    </bug>

</bugzilla>