-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Cherry-pick 1021d66. rdar://121960496
Crash under RenderLayer::calculateClipRects() when going into fullscreen https://bugs.webkit.org/show_bug.cgi?id=268891 rdar://121960496 Reviewed by Alan Baradlay. A combination of top layer and compositing backing sharing can cause a null de-ref when entering fullscreen, or using modal dialogs or popovers. The issue occurs when the renderer going into top layer participates in a backing sharing sequence, in the `RenderLayer::paintsIntoProvidedBacking()` sense. What happens in that case is that after the top layer configuration is changed we do a layout, after which `RenderLayerBacking::updateAfterLayout()` calls `RenderLayerBacking::updateCompositedBounds()` (this seems like an odd thing to do, because we're going to do a compositing update anyway, but a comment explains why we do it). This call requires that we compute clip rects, which calls `RenderLayer::canUseOffsetFromAncestor()`, which gets confused because the ancestor layer is no longer an ancestor. The fix is to clear any relevant backing sharing sequences when going into top layer, where "relevant" means backing sharing sequences in the stacking context of the layer that's going into top layer. We do that by calling into RenderLayerCompositor from `RenderLayer::establishesTopLayerWillChange()`. Normally traversing layers in a stacking context would walk the z-order lists, and this works for popover and dialog, but fullscreen triggers a style update before this code runs, which clears the z-order lists. So this stacking context traversal is written in terms of the RenderLayer tree (like `collectLayers()`). * LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-dialog-expected.txt: Added. * LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-dialog.html: Added. * LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-fullscreen-expected.txt: Added. * LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-fullscreen-variant-expected.txt: Added. * LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-fullscreen-variant.html: Added. * LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-fullscreen.html: Added. * LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-popover-expected.txt: Added. * LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-popover.html: Added. * Source/WebCore/rendering/RenderLayer.cpp: (WebCore::RenderLayer::establishesTopLayerWillChange): (WebCore::RenderLayer::calculateClipRects const): (WebCore::outputPaintOrderTreeLegend): (WebCore::outputPaintOrderTreeRecursive): * Source/WebCore/rendering/RenderLayerCompositor.cpp: (WebCore::RenderLayerCompositor::establishesTopLayerWillChangeForLayer): (WebCore::clearBackingSharingWithinStackingContext): (WebCore::RenderLayerCompositor::clearBackingProviderSequencesInStackingContextOfLayer): * Source/WebCore/rendering/RenderLayerCompositor.h: Canonical link: https://commits.webkit.org/274290@main Identifier: 272448.536@safari-7618.1.15.10-branch
- Loading branch information
Showing
11 changed files
with
367 additions
and
2 deletions.
There are no files selected for viewing
2 changes: 2 additions & 0 deletions
2
...utTests/compositing/shared-backing/top-layer/backing-sharing-split-by-dialog-expected.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,2 @@ | ||
x x | ||
Test passes if it does not crash. |
77 changes: 77 additions & 0 deletions
77
LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-dialog.html
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,77 @@ | ||
<!DOCTYPE html> | ||
<html> | ||
<head> | ||
<style> | ||
.negative-z { | ||
position: absolute; | ||
top: 20px; | ||
left: 20px; | ||
z-index: -1; | ||
width: 20px; | ||
height: 20px; | ||
border: 1px solid blue; | ||
} | ||
|
||
.transformed { | ||
transform: translateZ(0); | ||
} | ||
|
||
.relpos { | ||
position: relative; | ||
height: 500px; | ||
height: 600px; | ||
margin: 20px 40px; | ||
border: 2px solid gray; | ||
} | ||
|
||
dialog { | ||
position: relative !important; | ||
display: block; | ||
margin: 0px auto; | ||
width: 100%; | ||
height: 100%; | ||
background-color: rgba(0, 0, 0, 0.5); | ||
overflow: hidden; | ||
} | ||
|
||
.abspos { | ||
position: absolute; | ||
z-index: 2; | ||
width: 500px; | ||
height: 200px; | ||
background-color: green; | ||
} | ||
</style> | ||
<script> | ||
if (window.testRunner) { | ||
testRunner.dumpAsText(); | ||
testRunner.waitUntilDone(); | ||
} | ||
|
||
function showDialog() | ||
{ | ||
let dialog = document.getElementsByTagName('dialog')[0]; | ||
dialog.showModal(); | ||
} | ||
|
||
window.addEventListener('load', () => { | ||
setTimeout(() => { | ||
showDialog(); | ||
if (window.testRunner) | ||
testRunner.notifyDone(); | ||
}, 0); | ||
}, false); | ||
</script> | ||
</head> | ||
<body> | ||
<div class="negative-z"> | ||
x | ||
<div class="negative-z transformed">x</div> | ||
</div> | ||
<div class="relpos"> | ||
<dialog> | ||
<div class="abspos">Test passes if it does not crash.</div> | ||
</dialog> | ||
</div> | ||
</body> | ||
</html> |
2 changes: 2 additions & 0 deletions
2
...sts/compositing/shared-backing/top-layer/backing-sharing-split-by-fullscreen-expected.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,2 @@ | ||
x x | ||
Test passes if it does not crash. |
2 changes: 2 additions & 0 deletions
2
...ositing/shared-backing/top-layer/backing-sharing-split-by-fullscreen-variant-expected.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,2 @@ | ||
x x | ||
Test passes if it does not crash.. |
82 changes: 82 additions & 0 deletions
82
...sts/compositing/shared-backing/top-layer/backing-sharing-split-by-fullscreen-variant.html
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,82 @@ | ||
<!DOCTYPE html> | ||
<html> | ||
<head> | ||
<style> | ||
.negative-z { | ||
position: absolute; | ||
top: 20px; | ||
left: 20px; | ||
z-index: -1; | ||
width: 20px; | ||
height: 20px; | ||
border: 1px solid blue; | ||
} | ||
|
||
.transformed { | ||
transform: translateZ(0); | ||
} | ||
|
||
.relpos { | ||
position: relative; | ||
height: 500px; | ||
height: 600px; | ||
margin: 20px 40px; | ||
border: 2px solid gray; | ||
} | ||
|
||
.fullscreen { | ||
position: relative; | ||
margin: 0px auto; | ||
width: 100%; | ||
height: 100%; | ||
background-color: rgba(0, 0, 0, 0.5); | ||
overflow: hidden; | ||
} | ||
|
||
.abspos { | ||
position: absolute; | ||
z-index: 2; | ||
width: 500px; | ||
height: 165px; | ||
background-color: green; | ||
} | ||
</style> | ||
<script> | ||
if (window.testRunner) { | ||
testRunner.dumpAsText(); | ||
testRunner.waitUntilDone(); | ||
} | ||
|
||
function requestFullscreen() | ||
{ | ||
let fullscreen = document.querySelector('.fullscreen'); | ||
|
||
fullscreen.addEventListener("fullscreenchange", () => { | ||
if (window.testRunner) | ||
testRunner.notifyDone(); | ||
}); | ||
|
||
internals.withUserGesture(() => { | ||
fullscreen.requestFullscreen(); | ||
}); | ||
} | ||
|
||
window.addEventListener('load', () => { | ||
setTimeout(() => { | ||
requestFullscreen(); | ||
}, 0); | ||
}, false); | ||
</script> | ||
</head> | ||
<body> | ||
<div class="negative-z"> | ||
x | ||
<div class="negative-z transformed">x</div> | ||
</div> | ||
<div class="relpos"> | ||
<div class="fullscreen"> | ||
<div class="abspos">Test passes if it does not crash..</div> | ||
</div> | ||
</div> | ||
</body> | ||
</html> |
82 changes: 82 additions & 0 deletions
82
LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-fullscreen.html
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,82 @@ | ||
<!DOCTYPE html> | ||
<html> | ||
<head> | ||
<style> | ||
.negative-z { | ||
position: absolute; | ||
top: 20px; | ||
left: 20px; | ||
z-index: -1; | ||
width: 20px; | ||
height: 20px; | ||
border: 1px solid blue; | ||
} | ||
|
||
.transformed { | ||
transform: translateZ(0); | ||
} | ||
|
||
.relpos { | ||
position: relative; | ||
height: 500px; | ||
height: 600px; | ||
margin: 20px 40px; | ||
border: 2px solid gray; | ||
} | ||
|
||
.fullscreen { | ||
position: relative; | ||
margin: 0px auto; | ||
width: 100%; | ||
height: 100%; | ||
background-color: rgba(0, 0, 0, 0.5); | ||
overflow: hidden; | ||
} | ||
|
||
.abspos { | ||
position: absolute; | ||
z-index: 2; | ||
width: 500px; | ||
height: 165px; | ||
background-color: green; | ||
} | ||
</style> | ||
<script> | ||
if (window.testRunner) { | ||
testRunner.dumpAsText(); | ||
testRunner.waitUntilDone(); | ||
} | ||
|
||
function requestFullscreen() | ||
{ | ||
let fullscreen = document.querySelector('.fullscreen'); | ||
|
||
fullscreen.addEventListener("fullscreenchange", () => { | ||
if (window.testRunner) | ||
testRunner.notifyDone(); | ||
}); | ||
|
||
internals.withUserGesture(() => { | ||
fullscreen.requestFullscreen(); | ||
}); | ||
} | ||
|
||
window.addEventListener('load', () => { | ||
setTimeout(() => { | ||
requestFullscreen(); | ||
}, 0); | ||
}, false); | ||
</script> | ||
</head> | ||
<body> | ||
<div class="negative-z"> | ||
x | ||
<div class="negative-z transformed">x</div> | ||
</div> | ||
<div class="relpos"> | ||
<div class="fullscreen"> | ||
<div class="abspos">Test passes if it does not crash.</div> | ||
</div> | ||
</div> | ||
</body> | ||
</html> |
2 changes: 2 additions & 0 deletions
2
...tTests/compositing/shared-backing/top-layer/backing-sharing-split-by-popover-expected.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,2 @@ | ||
x x | ||
Test passes if it does not crash. |
79 changes: 79 additions & 0 deletions
79
LayoutTests/compositing/shared-backing/top-layer/backing-sharing-split-by-popover.html
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,79 @@ | ||
<!DOCTYPE html> | ||
<html> | ||
<head> | ||
<style> | ||
.negative-z { | ||
position: absolute; | ||
top: 20px; | ||
left: 20px; | ||
z-index: -1; | ||
width: 20px; | ||
height: 20px; | ||
border: 1px solid blue; | ||
} | ||
|
||
.transformed { | ||
transform: translateZ(0); | ||
} | ||
|
||
.relpos { | ||
position: relative; | ||
height: 650px; | ||
height: 770px; | ||
margin: 20px 40px; | ||
border: 2px solid gray; | ||
} | ||
|
||
.popover { | ||
position: relative; | ||
margin: 0px auto; | ||
width: 100%; | ||
height: 100%; | ||
background-color: rgba(0, 0, 0, 0.5); | ||
overflow: hidden; | ||
display: block; | ||
} | ||
|
||
.abspos { | ||
position: absolute; | ||
z-index: 2; | ||
width: 500px; | ||
height: 165px; | ||
background-color: green; | ||
} | ||
</style> | ||
<script> | ||
if (window.testRunner) { | ||
testRunner.dumpAsText(); | ||
testRunner.waitUntilDone(); | ||
} | ||
|
||
function showPopover() | ||
{ | ||
let popover = document.querySelector('.popover'); | ||
popover.showPopover(); | ||
} | ||
|
||
window.addEventListener('load', () => { | ||
setTimeout(() => { | ||
showPopover(); | ||
if (window.testRunner) | ||
testRunner.notifyDone(); | ||
}, 0); | ||
}, false); | ||
</script> | ||
</head> | ||
<body> | ||
<div class="negative-z"> | ||
x | ||
<div class="negative-z transformed">x</div> | ||
</div> | ||
<div class="relpos"> | ||
<div popover class="popover" id="mypopover"> | ||
<div class="abspos"> | ||
Test passes if it does not crash. | ||
</div> | ||
</div> | ||
</div> | ||
</body> | ||
</html> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.