Created attachment 454214 [details] testcase Same assertion as in bug 570624, which ehsan fixed. ###!!! ASSERTION: called nsGenericElement::SetText: 'Error', file content/base/src/nsGenericElement.cpp, line 4953
The iframe in this test case doesn't have any significance. Jesse, I always thought that your fuzzing framework creates minimized test cases. Is that true? You may want to look into why this iframe remained in the generated test case.
Created attachment 454437 [details] simpler testcase
Attachment #454214 - Attachment is obsolete: true
Summary: "ASSERTION: called nsGenericElement::SetText" with spellcheck, iframe → "ASSERTION: called nsGenericElement::SetText" with spellcheck
Created attachment 454438 [details] [diff] [review] Patch (v1) The cause of the assertion was that the text control frame did not initialize its editor link for spellcheck attributes in nsTextControlFrame::AttributeChanged, but the content node did, which caused the frame and content node have an inconsistent state.
Assignee: nobody → ehsan
Status: NEW → ASSIGNED
Attachment #454438 - Flags: review?(roc)
(In reply to comment #3) > Created an attachment (id=454437) [details] > simpler testcase Thanks, but I just wanted to point this out for your attention in case this is something to fix in the fuzzer itself! :-)
Attachment #454438 - Flags: review?(roc) → review+
Status: ASSIGNED → RESOLVED
Last Resolved: 8 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla1.9.3b1
You need to log in before you can comment on or make changes to this bug.