Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(657)

Unified Diff: LayoutTests/fast/flexbox/order-iterator-crash.html

Issue 19558006: Heap-use-after-free in WebCore::RenderFlexibleBox::firstLineBoxBaseline (Closed) Base URL: svn://svn.chromium.org/blink/trunk
Patch Set: Removed bad FINAL Created 7 years, 5 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: LayoutTests/fast/flexbox/order-iterator-crash.html
diff --git a/LayoutTests/fast/flexbox/order-iterator-crash.html b/LayoutTests/fast/flexbox/order-iterator-crash.html
new file mode 100644
index 0000000000000000000000000000000000000000..2b519664c713755e8095fec850ad1bfa52ecdf58
--- /dev/null
+++ b/LayoutTests/fast/flexbox/order-iterator-crash.html
@@ -0,0 +1,12 @@
+<div>This test has passed if it doesn't crash under ASAN.</div>
inferno 2013/07/19 20:25:08 nit: we should add a <!DOCTYPE html>
Julien - ping for review 2013/07/19 20:52:31 Nope, this test requires quirks mode :(
+<style>
+* { display: flex; }
+</style>
+<table><td id="crashy"></td></table>
+<script>
+if (window.testRunner)
+ testRunner.dumpAsText();
+
+crashy.offsetLeft;
+crashy.parentNode.removeChild(crashy);
+</script>

Powered by Google App Engine
This is Rietveld 408576698