Remove AllowMarkStyleDirtyFromRecalcScope for <img> fallbacks

During HTMLImageElement::AdjustStyle, we do something very shady:
we poke into the UA shadow and mutate the inline style of some
of the elements in there. This causes style to be marked dirty
*during* style recalc, which is not a desirable situation.
The behavior would normally trigger a DCHECK, but it is currently
suppressed with by AllowMarkStyleDirtyFromRecalcScope.

Marking style dirty deeper in the current subtree works (sort of),
because we'll eventually reach those elements during the current
style recalc process anyway, so ultimately the dirtiness is
cleared. However, StyleResolver::ResolveStyle can also be called
*outside* of style recalc. For example, when producing styles
for kFirstLineInherited, we call ResolveStyle during *layout*.
In this case, there is no greater style recalc process ongoing,
so the dirtiness isn't cleared, and we trigger DCHECKs
(Issue 1486128).

This CL addresses the problem as follows:

 - When adjusting the style for the UA shadow host (<img>),
   we capture the state descendants care about into an
   inherited object StyleHostData.
 - Later, when recalculating the style of descendants (inside
   the shadow), we give the elements an opportunity to produce
   an "extra" CSSPropertyValueSet which is added into the cascade.
   This CSSPropertyValueSet can be produced based on the previously
   captured StyleHostData.

Fixed: 953707, 1486128
Change-Id: I856eaa95df2b68fb35cbe00714f9a43af9537d4f
diff --git a/css/css-pseudo/first-line-input-image-crash.html b/css/css-pseudo/first-line-input-image-crash.html
new file mode 100644
index 0000000..66bd033
--- /dev/null
+++ b/css/css-pseudo/first-line-input-image-crash.html
@@ -0,0 +1,9 @@
+<!DOCTYPE html>
+<title>Don't crash when using ::first-line and &lt;input type=image&gt;</title>
+<link rel="help" href="https://crbug.com/1486128">
+<style>
+  * { display:initial; }
+  *::first-line { color:green; }
+</style>
+<div>PASS if no crash</div>
+<input type="image">