Automatic update from web-platform-tests
[@scope] Avoid infinite recursion when extracting bucketing values
When extracting bucketing values, we treat :scope similarly
to '&' for nesting, i.e. we look at the <scope-start> selector
of the @scope rule (if present), and bucket against that selector.
However, in the inner call to ExtractBucketingValues, we pass our
own `style_scope` rather than the parent scope, leading to an
infinite recursion for e.g. @scope (:scope) { :scope {} }.
Note: we have a similar treatment of :scope in the SelectorFilter
(CollectDescendantSelectorIdentifierHashes). That code is already
recursing with style_scope->Parent(), so we do not have
the same bug there.
Fixed: 454830626
Change-Id: I568ccb93dadc21fd72a13318e51cb31e3ab11298
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7079582
Reviewed-by: Rune Lillesveen <futhark@chromium.org>
Commit-Queue: Anders Hartvoll Ruud <andruud@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1535864}
--
wpt-commits: 86246912eb046e7987dd69a7c63e3f28cab39af5
wpt-pr: 55674
14 lines
283 B
HTML
14 lines
283 B
HTML
<!DOCTYPE html>
|
|
<title>Crash with :scope in both subject and prelude</title>
|
|
<link rel="help" href="https://issues.chromium.org/issues/454830626">
|
|
<style>
|
|
@scope (.a) {
|
|
@scope(:scope) {
|
|
:scope {
|
|
background: green;
|
|
}
|
|
}
|
|
}
|
|
</style>
|
|
<div class=a>PASS if no crash</div>
|