<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>6951</bug_id>
          
          <creation_ts>2006-01-30 18:10:24 -0800</creation_ts>
          <short_desc>hang due to infinitely growing points array because parsePoints loop is broken</short_desc>
          <delta_ts>2011-11-11 08:29:15 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>SVG</component>
          <version>420+</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.4</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://www.treebuilder.de/default.asp?file=606899.xml</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>HasReduction, SVGHitList</keywords>
          <priority>P1</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>6890</dependson>
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Eric Seidel (no email)">eric</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>joost</cc>
    
    <cc>pnormand</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>30685</commentid>
    <comment_count>0</comment_count>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2006-01-30 18:10:24 -0800</bug_when>
    <thetext>&quot;Brown&quot; SVG hangs safari

Crash/Data Loss, SVGHitList, p2.

http://www.treebuilder.de/default.asp?file=606899.xml</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>31332</commentid>
    <comment_count>1</comment_count>
      <attachid>6249</attachid>
    <who name="Joost de Valk (AlthA)">joost</who>
    <bug_when>2006-02-04 10:25:53 -0800</bug_when>
    <thetext>Created attachment 6249
testcase

This testcase still hangs WebKit. The var &quot;d&quot; is initialized without a value, and then used to set an attribute, if the var &quot;d&quot; is given a value, the testcase no longer hangs Safari.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>32144</commentid>
    <comment_count>2</comment_count>
    <who name="Darin Adler">darin</who>
    <bug_when>2006-02-11 10:49:46 -0800</bug_when>
    <thetext>Might be nice to have a reduction that didn&apos;t involve SVG.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>32291</commentid>
    <comment_count>3</comment_count>
    <who name="Darin Adler">darin</who>
    <bug_when>2006-02-12 21:40:51 -0800</bug_when>
    <thetext>The hang doesn&apos;t seem to have anything to do with the unintiailized JS variable. It&apos;s inside SVG path parsing.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>32293</commentid>
    <comment_count>4</comment_count>
    <who name="Darin Adler">darin</who>
    <bug_when>2006-02-12 21:52:50 -0800</bug_when>
    <thetext>The reason for the hang is that SVGPolyParser::parsePoints ends up calling parseMappedAttribute over and over again, because each time it calls svgPolyTo it then appends a new item to the points which triggers the attribute mapping machinery again over and over again, so it just keeps making the points array longer and longer forever.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>32309</commentid>
    <comment_count>5</comment_count>
    <who name="Alexander Kellett">a</who>
    <bug_when>2006-02-13 02:40:30 -0800</bug_when>
    <thetext>i&apos;ve already got a fix for this one, actually its not due to notifications, its just because parsePoints never steps forward through the empty string, it just infinite loops over nothing</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>35334</commentid>
    <comment_count>6</comment_count>
    <who name="Darin Adler">darin</who>
    <bug_when>2006-03-06 15:08:47 -0800</bug_when>
    <thetext>Alex landed a fix for this.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>500793</commentid>
    <comment_count>7</comment_count>
    <who name="Martin Robinson">mrobinson</who>
    <bug_when>2011-11-11 08:29:15 -0800</bug_when>
    <thetext>*** Bug 71454 has been marked as a duplicate of this bug. ***</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>6249</attachid>
            <date>2006-02-04 10:25:53 -0800</date>
            <delta_ts>2006-02-04 10:25:53 -0800</delta_ts>
            <desc>testcase</desc>
            <filename>brown.svg</filename>
            <type>image/svg+xml</type>
            <size>432</size>
            <attacher name="Joost de Valk (AlthA)">joost</attacher>
            
              <data encoding="base64">PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciDQogeG1sbnM6eGxpbms9Imh0
dHA6Ly93d3cudzMub3JnLzE5OTkveGxpbmsiDQogb25sb2FkPSJpbml0KCkiPgoNCg0KPHNjcmlw
dD4NCgk8IVtDREFUQVsNCgkJdmFyIHN2Z25zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIN
CgkJdmFyIGQNCgkJDQoJCWZ1bmN0aW9uIGluaXQoKXsNCgkJCXZhciBwb2w9ZG9jdW1lbnQuY3Jl
YXRlRWxlbWVudE5TKHN2Z25zLCJwb2x5bGluZSIpDQoJCQlwb2wuc2V0QXR0cmlidXRlKCJwb2lu
dHMiLGQpDQoJCQl2YXIgaGlzdD1kb2N1bWVudC5nZXRFbGVtZW50QnlJZCgiaGlzdG9ncmFtbSIp
DQoJCQloaXN0LmFwcGVuZENoaWxkKHBvbCkNCgkJfQogDQoJXV0+DQo8L3NjcmlwdD4NCiANCiA8
ZyBpZD0iaGlzdG9ncmFtbSI+PC9nPgoNCg0KPC9zdmc+
</data>

          </attachment>
      

    </bug>

</bugzilla>