[Autofill][Blink] Fix collection of form-associated elements
HTMLFormElement::CollectListedElements() collects the listed elements
associated with the form. Additionally, it recursively descends into
shadow trees.
Before this CL, the traversal used StartsAfter(). In the following
example, the traversal therefore reaches the <div> outside of the
<form>:
<form>
<div>
<template shadowrootmode=open>
<input>
</template>
</div>
</form>
<div>
<template shadowrootmode=open>
<input id=t>
</template>
</div>
This is not just inefficient but also a bug for the following reason.
The traversal only adds elements to the vector of listed elements that
are descendants of the form. In some cases, CollectListedElements()
attempts to optimize away the IsDescendantOf() call
(`root_is_descendant`). The idea is if the root (of the traversal)
is a descendant of the form, then also every visited element is a
descendant.
That however is not the case because the traversal, due to
StartsAfter(), goes beyond the descendants of that root.
As a result, CollectListedElements() recursively calls itself on the
shadow tree that contains `t` and then erroneously adds `t` to the
listed elements of the form.
This CL therefore replaces StartsAfter() with DescendantsOf() in
CollectListedElements().
It also does the same in CollectImageElements() as another performance
improvement.
Bug: 349121116, 41276841, 347059988
Change-Id: Ia6b201d0ccc853cf337579df54e70af6c800e840
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/5648060
Reviewed-by: Mason Freed <masonf@chromium.org>
Code-Coverage: findit-for-me@appspot.gserviceaccount.com <findit-for-me@appspot.gserviceaccount.com>
Reviewed-by: Jan Keitel <jkeitel@google.com>
Commit-Queue: Christoph Schwering <schwering@google.com>
Cr-Commit-Position: refs/heads/main@{#1320333}
Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
The project's web site is https://www.chromium.org.
To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.
Documentation in the source is rooted in docs/README.md.
Learn how to Get Around the Chromium Source Code Directory Structure.
For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.
If you found a bug, please file it at https://crbug.com/new.