Before the regressing bug we relied on GetRangeInsertionPoint to do this, but it's not really necessary. If the root element is on the range deal with it, otherwise bail, which is what we were already doing. Differential Revision: https://phabricator.services.mozilla.com/D278124
11 lines
282 B
HTML
11 lines
282 B
HTML
<html>
|
|
<link rel="help" href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008590">
|
|
<script>
|
|
document.addEventListener("DOMContentLoaded", () => {
|
|
document.documentElement.replaceWith(a)
|
|
})
|
|
</script>
|
|
<dl id="a">a</dl>
|
|
</html>
|
|
<!-- This comment is needed to trigger the crash -->
|