Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(6)

Unified Diff: Source/core/rendering/RenderGrid.cpp

Issue 493093002: [CSS Grid Layout] Heap-buffer-overflow in std::sort() (Closed) Base URL: https://chromium.googlesource.com/chromium/blink.git@master
Patch Set: Created 6 years, 4 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « LayoutTests/fast/css-grid-layout/grid-strict-ordering-crash-2-expected.txt ('k') | no next file » | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: Source/core/rendering/RenderGrid.cpp
diff --git a/Source/core/rendering/RenderGrid.cpp b/Source/core/rendering/RenderGrid.cpp
index 4f474611800d3c8b62ce686754120dfe0f489ba7..609d324dc5a4b0631b29a9dcba7c3b5eee0fa04e 100644
--- a/Source/core/rendering/RenderGrid.cpp
+++ b/Source/core/rendering/RenderGrid.cpp
@@ -742,11 +742,11 @@ void RenderGrid::resolveContentBasedTrackSizingFunctionsForItems(GridTrackSizing
static bool sortByGridTrackGrowthPotential(const GridTrack* track1, const GridTrack* track2)
{
- if (track1->m_maxBreadth == infinity)
- return track2->m_maxBreadth == infinity;
+ if (track1->m_maxBreadth == infinity && track2->m_maxBreadth == infinity)
Julien - ping for review 2014/09/08 21:10:13 We should probably add a comment about how this ma
+ return false;
- if (track2->m_maxBreadth == infinity)
- return true;
+ if (track1->m_maxBreadth == infinity || track2->m_maxBreadth == infinity)
+ return track2->m_maxBreadth == infinity;
return (track1->m_maxBreadth - track1->m_usedBreadth) < (track2->m_maxBreadth - track2->m_usedBreadth);
}
« no previous file with comments | « LayoutTests/fast/css-grid-layout/grid-strict-ordering-crash-2-expected.txt ('k') | no next file » | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698