Created attachment 417225 [details]
testcase 1 - ASSERTION: Some pres arena objects were not freed
###!!! ASSERTION: Some pres arena objects were not freed: 'mPresArenaAllocCount == 0', file /Users/jruderman/mozilla-central/layout/base/nsPresShell.cpp, line 1550
This assertion often indicates the presence of a security hole (which frame poisoning does not mitigate).
Created attachment 417226 [details]
testcase 2 - poison crash [@ nsLayoutUtils::GetNextContinuationOrSpecialSibling]
Caused by bug 504524.
Created attachment 417273 [details] [diff] [review]
Comment on attachment 417273 [details] [diff] [review]
(seems like an additional piece of the fix in bug 523468)
This also fixes bug 525986.
(In reply to comment #4)
> (seems like an additional piece of the fix in bug 523468)
(In reply to comment #5)
> This also fixes bug 525986.
from the patch we're using an uninitialzed irs.mLineLayout?
No. The constructor initializes mLineLayout to null.
I need to check this test in.