Bug 1343937 - Fix a crash in nsWrapperCache.h

* Implement and use GetInFlowParent
* Exempt scrollbar NAC from the new NAC semantics

Tag #1375
This commit is contained in:
Matt A. Tobin 2020-04-16 17:51:36 -04:00 • committed by Roy Tam
commit 8e51f64cad
5 changed files with 41 additions and 4 deletions

View file

@ -8951,10 +8951,10 @@ GetCorrectedParent(const nsIFrame* aFrame)
nsIContent* content = aFrame->GetContent();
Element* element =
content && content->IsElement() ? content->AsElement() : nullptr;
if (element && element->IsNativeAnonymous() &&
if (element && element->IsNativeAnonymous() && !element->IsNativeScrollbarContent() &&
element->GetPseudoElementType() == aFrame->StyleContext()->GetPseudoType()) {
while (parent->GetContent() && parent->GetContent()->IsNativeAnonymous()) {
parent = parent->GetParent();
parent = parent->GetInFlowParent();
}
}

View file

@ -721,6 +721,13 @@ public:
* Accessor functions for geometric parent.
*/
nsContainerFrame* GetParent() const { return mParent; }
/**
* Gets the parent of a frame, using the parent of the placeholder for
* out-of-flow frames.
*/
inline nsContainerFrame* GetInFlowParent();
/**
* Set this frame's parent to aParent.
* If the frame may have moved into or out of a scrollframe's

View file

@ -8,8 +8,10 @@
#define nsIFrameInlines_h___
#include "nsContainerFrame.h"
#include "nsPlaceholderFrame.h"
#include "nsStyleStructInlines.h"
#include "nsCSSAnonBoxes.h"
#include "nsFrameManager.h"
bool
nsIFrame::IsFlexItem() const
@ -160,4 +162,15 @@ nsIFrame::BaselineBOffset(mozilla::WritingMode aWM,
return SynthesizeBaselineBOffsetFromBorderBox(aWM, aBaselineGroup);
}
nsContainerFrame*
nsIFrame::GetInFlowParent()
{
if (GetStateBits() & NS_FRAME_OUT_OF_FLOW) {
nsFrameManager* fm = PresContext()->FrameManager();
return fm->GetPlaceholderFrameFor(FirstContinuation())->GetParent();
}
return GetParent();
}
#endif