Remove AllowMarkStyleDirtyFromRecalcScope for <img> fallbacks During HTMLImageElement::AdjustStyle, we do something very shady: we poke into the UA shadow and mutate the inline style of some of the elements in there. This causes style to be marked dirty *during* style recalc, which is not a desirable situation. The behavior would normally trigger a DCHECK, but it is currently suppressed with by AllowMarkStyleDirtyFromRecalcScope. Marking style dirty deeper in the current subtree works (sort of), because we'll eventually reach those elements during the current style recalc process anyway, so ultimately the dirtiness is cleared. However, StyleResolver::ResolveStyle can also be called *outside* of style recalc. For example, when producing styles for kFirstLineInherited, we call ResolveStyle during *layout*. In this case, there is no greater style recalc process ongoing, so the dirtiness isn't cleared, and we trigger DCHECKs (Issue 1486128). This CL addresses the problem as follows: - When adjusting the style for the UA shadow host (<img>), we capture the state descendants care about into an inherited object StyleHostData. - Later, when recalculating the style of descendants (inside the shadow), we give the elements an opportunity to produce an "extra" CSSPropertyValueSet which is added into the cascade. This CSSPropertyValueSet can be produced based on the previously captured StyleHostData. Fixed: 953707, 1486128 Change-Id: I856eaa95df2b68fb35cbe00714f9a43af9537d4f
diff --git a/css/css-pseudo/first-line-input-image-crash.html b/css/css-pseudo/first-line-input-image-crash.html new file mode 100644 index 0000000..66bd033 --- /dev/null +++ b/css/css-pseudo/first-line-input-image-crash.html
@@ -0,0 +1,9 @@ +<!DOCTYPE html> +<title>Don't crash when using ::first-line and <input type=image></title> +<link rel="help" href="https://crbug.com/1486128"> +<style> + * { display:initial; } + *::first-line { color:green; } +</style> +<div>PASS if no crash</div> +<input type="image">