<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" /><style type="text/css"><!--
#msg dl { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fc0 solid; padding: 6px; }
#msg ul, pre { overflow: auto; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<title>[20725] trunk/WebCore</title>
</head>
<body>

<div id="msg">
<dl>
<dt>Revision</dt> <dd><a href="http://trac.webkit.org/projects/webkit/changeset/20725">20725</a></dd>
<dt>Author</dt> <dd>ggaren</dd>
<dt>Date</dt> <dd>2007-04-05 12:33:52 -0700 (Thu, 05 Apr 2007)</dd>
</dl>

<h3>Log Message</h3>
<pre>        Reviewed by Beth Dakin.

        More clean-up while fixing &lt;rdar://problem/5112273&gt; REGRESSION(TOT): 
        Reproducible crash loading an old version of amazon.com as a web archive
        
        Layout tests pass.
        
        Removed more superfluous document NULL checks. (Node::document() never 
        returns NULL, and it asserts as much.)
        
        Merged some duplicate editing code into a static inline function.
        
        * page/mac/WebCoreFrameBridge.mm:
        (updateRenderingForBindings): Removed superfluous static_cast.</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunkWebCoreChangeLog">trunk/WebCore/ChangeLog</a></li>
<li><a href="#trunkWebCorebindingsjskjs_htmlcpp">trunk/WebCore/bindings/js/kjs_html.cpp</a></li>
<li><a href="#trunkWebCorebridgemacWebCoreAXObjectmm">trunk/WebCore/bridge/mac/WebCoreAXObject.mm</a></li>
<li><a href="#trunkWebCoreeditingEditorcpp">trunk/WebCore/editing/Editor.cpp</a></li>
<li><a href="#trunkWebCorehtmlHTMLInputElementcpp">trunk/WebCore/html/HTMLInputElement.cpp</a></li>
<li><a href="#trunkWebCorehtmlHTMLTextAreaElementcpp">trunk/WebCore/html/HTMLTextAreaElement.cpp</a></li>
<li><a href="#trunkWebCoreksvg2svgSVGAElementcpp">trunk/WebCore/ksvg2/svg/SVGAElement.cpp</a></li>
<li><a href="#trunkWebCoreksvg2svgSVGElementInstancecpp">trunk/WebCore/ksvg2/svg/SVGElementInstance.cpp</a></li>
<li><a href="#trunkWebCorepageContextMenuControllercpp">trunk/WebCore/page/ContextMenuController.cpp</a></li>
<li><a href="#trunkWebCorepageDragControllercpp">trunk/WebCore/page/DragController.cpp</a></li>
<li><a href="#trunkWebCorepagemacWebCoreFrameBridgemm">trunk/WebCore/page/mac/WebCoreFrameBridge.mm</a></li>
<li><a href="#trunkWebCorerenderingRenderObjectcpp">trunk/WebCore/rendering/RenderObject.cpp</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunkWebCoreChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/ChangeLog (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/ChangeLog        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/ChangeLog        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -1,3 +1,20 @@
</span><ins>+2007-04-05  Geoffrey Garen  &lt;ggaren@apple.com&gt;
+
+        Reviewed by Beth Dakin.
+
+        More clean-up while fixing &lt;rdar://problem/5112273&gt; REGRESSION(TOT): 
+        Reproducible crash loading an old version of amazon.com as a web archive
+        
+        Layout tests pass.
+        
+        Removed more superfluous document NULL checks. (Node::document() never 
+        returns NULL, and it asserts as much.)
+        
+        Merged some duplicate editing code into a static inline function.
+        
+        * page/mac/WebCoreFrameBridge.mm:
+        (updateRenderingForBindings): Removed superfluous static_cast.
+
</ins><span class="cx"> 2007-04-05  Adele Peterson  &lt;adele@apple.com&gt;
</span><span class="cx"> 
</span><span class="cx">         Reviewed by Darin.
</span></span></pre></div>
<a id="trunkWebCorebindingsjskjs_htmlcpp"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/bindings/js/kjs_html.cpp (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/bindings/js/kjs_html.cpp        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/bindings/js/kjs_html.cpp        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -753,9 +753,7 @@
</span><span class="cx"> {
</span><span class="cx">     HTMLElement* element = static_cast&lt;HTMLElement*&gt;(impl());
</span><span class="cx">     if (element-&gt;hasTagName(embedTag) || element-&gt;hasTagName(objectTag) || element-&gt;hasTagName(appletTag)) {
</span><del>-        Frame* frame = 0;
-        if (Document* doc = element-&gt;document())
-            frame = doc-&gt;frame();
</del><ins>+        Frame* frame = element-&gt;document()-&gt;frame();
</ins><span class="cx">         if (!frame)
</span><span class="cx">             return false;
</span><span class="cx">         KJSProxy *proxy = frame-&gt;scriptProxy();
</span></span></pre></div>
<a id="trunkWebCorebridgemacWebCoreAXObjectmm"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/bridge/mac/WebCoreAXObject.mm (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/bridge/mac/WebCoreAXObject.mm        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/bridge/mac/WebCoreAXObject.mm        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -1334,13 +1334,8 @@
</span><span class="cx"> 
</span><span class="cx">     // try to use the document view from the first position, so that nested WebAreas work,
</span><span class="cx">     // but fall back to the top level doc if we do not find it easily
</span><del>-    FrameView* frameView = 0;
</del><span class="cx">     RenderObject* renderer = startVisiblePosition.deepEquivalent().node()-&gt;renderer();
</span><del>-    if (renderer) {
-        Document* doc = renderer-&gt;document();
-        if (doc)
-            frameView = doc-&gt;view();
-    }
</del><ins>+    FrameView* frameView = renderer ? renderer-&gt;document()-&gt;view() : 0;
</ins><span class="cx">     if (!frameView)
</span><span class="cx">         frameView = [self frameView];
</span><span class="cx">     NSView* view = frameView-&gt;getView();
</span></span></pre></div>
<a id="trunkWebCoreeditingEditorcpp"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/editing/Editor.cpp (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/editing/Editor.cpp        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/editing/Editor.cpp        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -1114,48 +1114,33 @@
</span><span class="cx">     return true;
</span><span class="cx"> }
</span><span class="cx"> 
</span><ins>+static inline Frame* targetFrame(Frame* frame, Event* evt)
+{
+    Node* node = evt ? evt-&gt;target()-&gt;toNode() : 0;
+    if (!node)
+        return frame;
+    return node-&gt;document()-&gt;frame();
+}
+
</ins><span class="cx"> static bool execInsertTab(Frame* frame, Event* evt)
</span><span class="cx"> {
</span><del>-    Frame* targetFrame = frame;
-    if (evt) {
-        if (Node* node = evt-&gt;target()-&gt;toNode())
-            if (Document* doc = node-&gt;document())
-                targetFrame = doc-&gt;frame();
-    }
-    return targetFrame-&gt;eventHandler()-&gt;handleTextInputEvent(&quot;\t&quot;, evt, false, false);
</del><ins>+    return targetFrame(frame, evt)-&gt;eventHandler()-&gt;handleTextInputEvent(&quot;\t&quot;, evt, false, false);
</ins><span class="cx"> }
</span><span class="cx"> 
</span><span class="cx"> static bool execInsertBacktab(Frame* frame, Event* evt)
</span><span class="cx"> {
</span><del>-    Frame* targetFrame = frame;
-    if (evt) {
-        if (Node* node = evt-&gt;target()-&gt;toNode())
-            if (Document* doc = node-&gt;document())
-                targetFrame = doc-&gt;frame();
-    }
-    return targetFrame-&gt;eventHandler()-&gt;handleTextInputEvent(&quot;\t&quot;, evt, false, true);
</del><ins>+    return targetFrame(frame, evt)-&gt;eventHandler()-&gt;handleTextInputEvent(&quot;\t&quot;, evt, false, true);
</ins><span class="cx"> }
</span><span class="cx"> 
</span><span class="cx"> static bool execInsertNewline(Frame* frame, Event* evt)
</span><span class="cx"> {
</span><del>-    Frame* targetFrame = frame;
-    if (evt) {
-        if (Node* node = evt-&gt;target()-&gt;toNode())
-            if (Document* doc = node-&gt;document())
-                targetFrame = doc-&gt;frame();
-    }
</del><ins>+    Frame* targetFrame = WebCore::targetFrame(frame, evt);
</ins><span class="cx">     return targetFrame-&gt;eventHandler()-&gt;handleTextInputEvent(&quot;\n&quot;, evt, !targetFrame-&gt;editor()-&gt;canEditRichly());
</span><span class="cx"> }
</span><span class="cx"> 
</span><span class="cx"> static bool execInsertLineBreak(Frame* frame, Event* evt)
</span><span class="cx"> {
</span><del>-    Frame* targetFrame = frame;
-    if (evt) {
-        if (Node* node = evt-&gt;target()-&gt;toNode())
-            if (Document* doc = node-&gt;document())
-                targetFrame = doc-&gt;frame();
-    }
-    return targetFrame-&gt;eventHandler()-&gt;handleTextInputEvent(&quot;\n&quot;, evt, true);
</del><ins>+    return targetFrame(frame, evt)-&gt;eventHandler()-&gt;handleTextInputEvent(&quot;\n&quot;, evt, true);
</ins><span class="cx"> }
</span><span class="cx"> 
</span><span class="cx"> // Enabled functions
</span></span></pre></div>
<a id="trunkWebCorehtmlHTMLInputElementcpp"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/html/HTMLInputElement.cpp (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/html/HTMLInputElement.cpp        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/html/HTMLInputElement.cpp        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -213,7 +213,7 @@
</span><span class="cx">             // Restore the cached selection.
</span><span class="cx">             setSelectionRange(cachedSelStart, cachedSelEnd); 
</span><span class="cx">         
</span><del>-        if (document() &amp;&amp; document()-&gt;frame()) {
</del><ins>+        if (document()-&gt;frame()) {
</ins><span class="cx">             document()-&gt;frame()-&gt;editor()-&gt;didBeginEditing();
</span><span class="cx">             document()-&gt;frame()-&gt;revealSelection();
</span><span class="cx">         }
</span></span></pre></div>
<a id="trunkWebCorehtmlHTMLTextAreaElementcpp"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/html/HTMLTextAreaElement.cpp (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/html/HTMLTextAreaElement.cpp        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/html/HTMLTextAreaElement.cpp        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -231,7 +231,7 @@
</span><span class="cx">         // Restore the cached selection.  This matches other browsers' behavior.
</span><span class="cx">         setSelectionRange(cachedSelStart, cachedSelEnd); 
</span><span class="cx"> 
</span><del>-    if (document() &amp;&amp; document()-&gt;frame())
</del><ins>+    if (document()-&gt;frame())
</ins><span class="cx">         document()-&gt;frame()-&gt;revealSelection();
</span><span class="cx"> }
</span><span class="cx"> 
</span></span></pre></div>
<a id="trunkWebCoreksvg2svgSVGAElementcpp"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/ksvg2/svg/SVGAElement.cpp (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/ksvg2/svg/SVGAElement.cpp        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/ksvg2/svg/SVGAElement.cpp        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -114,7 +114,7 @@
</span><span class="cx"> 
</span><span class="cx">         String url = parseURL(href());
</span><span class="cx">         if (!evt-&gt;defaultPrevented())
</span><del>-            if (document() &amp;&amp; document()-&gt;frame())
</del><ins>+            if (document()-&gt;frame())
</ins><span class="cx">                 document()-&gt;frame()-&gt;loader()-&gt;urlSelected(document()-&gt;completeURL(url), target, evt);
</span><span class="cx"> 
</span><span class="cx">         evt-&gt;setDefaultHandled();
</span></span></pre></div>
<a id="trunkWebCoreksvg2svgSVGElementInstancecpp"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/ksvg2/svg/SVGElementInstance.cpp (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/ksvg2/svg/SVGElementInstance.cpp        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/ksvg2/svg/SVGElementInstance.cpp        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -48,8 +48,7 @@
</span><span class="cx">     ASSERT(m_element);
</span><span class="cx"> 
</span><span class="cx">     // Register as instance for passed element.
</span><del>-    if (Document* document = m_element-&gt;document())
-        document-&gt;accessSVGExtensions()-&gt;mapInstanceToElement(this, m_element.get());
</del><ins>+    m_element-&gt;document()-&gt;accessSVGExtensions()-&gt;mapInstanceToElement(this, m_element.get());
</ins><span class="cx"> }
</span><span class="cx"> 
</span><span class="cx"> SVGElementInstance::~SVGElementInstance()
</span><span class="lines">@@ -58,8 +57,7 @@
</span><span class="cx">         child-&gt;setParent(0);
</span><span class="cx"> 
</span><span class="cx">     // Deregister as instance for passed element.
</span><del>-    if (Document* document = m_element-&gt;document())
-        document-&gt;accessSVGExtensions()-&gt;removeInstanceMapping(this, m_element.get());
</del><ins>+    m_element-&gt;document()-&gt;accessSVGExtensions()-&gt;removeInstanceMapping(this, m_element.get());
</ins><span class="cx"> }
</span><span class="cx"> 
</span><span class="cx"> SVGElement* SVGElementInstance::correspondingElement() const
</span></span></pre></div>
<a id="trunkWebCorepageContextMenuControllercpp"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/page/ContextMenuController.cpp (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/page/ContextMenuController.cpp        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/page/ContextMenuController.cpp        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -83,9 +83,8 @@
</span><span class="cx">     IntPoint point = IntPoint(mouseEvent-&gt;pageX(), mouseEvent-&gt;pageY());
</span><span class="cx">     HitTestResult result(point);
</span><span class="cx"> 
</span><del>-    if (Document* document = event-&gt;target()-&gt;toNode()-&gt;document())
-        if (Frame* frame = document-&gt;frame())
-            result = frame-&gt;eventHandler()-&gt;hitTestResultAtPoint(point, false);
</del><ins>+    if (Frame* frame = event-&gt;target()-&gt;toNode()-&gt;document()-&gt;frame())
+        result = frame-&gt;eventHandler()-&gt;hitTestResultAtPoint(point, false);
</ins><span class="cx">     
</span><span class="cx">     if (!result.innerNonSharedNode())
</span><span class="cx">         return;
</span></span></pre></div>
<a id="trunkWebCorepageDragControllercpp"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/page/DragController.cpp (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/page/DragController.cpp        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/page/DragController.cpp        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -102,7 +102,7 @@
</span><span class="cx">         if (dragData-&gt;containsURL()) {
</span><span class="cx">             String title;
</span><span class="cx">             String url = dragData-&gt;asURL(&amp;title);
</span><del>-            if (document &amp;&amp; !url.isEmpty()) {
</del><ins>+            if (!url.isEmpty()) {
</ins><span class="cx">                 ExceptionCode ec;
</span><span class="cx">                 RefPtr&lt;HTMLAnchorElement&gt; anchor = static_cast&lt;HTMLAnchorElement*&gt;(document-&gt;createElement(&quot;a&quot;, ec).get());
</span><span class="cx">                 anchor-&gt;setHref(url);
</span></span></pre></div>
<a id="trunkWebCorepagemacWebCoreFrameBridgemm"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/page/mac/WebCoreFrameBridge.mm (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/page/mac/WebCoreFrameBridge.mm        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/page/mac/WebCoreFrameBridge.mm        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -144,8 +144,7 @@
</span><span class="cx">     if (!window)
</span><span class="cx">         return;
</span><span class="cx">         
</span><del>-    Document* doc = static_cast&lt;Document*&gt;(window-&gt;frame()-&gt;document());
-    if (doc)
</del><ins>+    if (Document* doc = window-&gt;frame()-&gt;document())
</ins><span class="cx">         doc-&gt;updateRendering();
</span><span class="cx"> }
</span><span class="cx"> 
</span></span></pre></div>
<a id="trunkWebCorerenderingRenderObjectcpp"></a>
<div class="modfile"><h4>Modified: trunk/WebCore/rendering/RenderObject.cpp (20724 => 20725)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/WebCore/rendering/RenderObject.cpp        2007-04-05 18:41:04 UTC (rev 20724)
+++ trunk/WebCore/rendering/RenderObject.cpp        2007-04-05 19:33:52 UTC (rev 20725)
</span><span class="lines">@@ -2488,7 +2488,7 @@
</span><span class="cx"> void RenderObject::destroy()
</span><span class="cx"> {
</span><span class="cx">     // If this renderer is being autoscrolled, stop the autoscroll timer
</span><del>-    if (document() &amp;&amp; document()-&gt;frame() &amp;&amp; document()-&gt;frame()-&gt;eventHandler()-&gt;autoscrollRenderer() == this)
</del><ins>+    if (document()-&gt;frame() &amp;&amp; document()-&gt;frame()-&gt;eventHandler()-&gt;autoscrollRenderer() == this)
</ins><span class="cx">         document()-&gt;frame()-&gt;eventHandler()-&gt;stopAutoscrollTimer(true);
</span><span class="cx"> 
</span><span class="cx">     if (m_hasCounterNodeMap)
</span></span></pre>
</div>
</div>

</body>
</html>