Automatic update from web-platform-tests Forbid generated images as cursor via light-dark() (#60469) The 'cursor' property forbids generated images, but light-dark() resolved its branches without honoring that policy, letting a gradient become a cursor image. Gradients are re-instantiated on every style recalc, so the per-instance image-observer bookkeeping in UpdateCursorImages drifted and RemoveClient() hit a SECURITY_CHECK during layout teardown. Bug: 518872187 Change-Id: I45cab2c148b60a673f1381e560d90d6ce9d57e9c Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7898340 Reviewed-by: Rune Lillesveen <futhark@chromium.org> Commit-Queue: Jason Leo <cgqaq@chromium.org> Cr-Commit-Position: refs/heads/main@{#1642106} Co-authored-by: Jason Leo <cgqaq@chromium.org> -- wpt-commits: abb03d330520ffdf458433d209e3fbd9b2842c74 wpt-pr: 60469
32 lines
1.4 KiB
HTML
32 lines
1.4 KiB
HTML
<!DOCTYPE html>
|
|
<html>
|
|
<head>
|
|
<meta charset="utf-8">
|
|
<title>CSS UI Level 3: parsing cursor with invalid values</title>
|
|
<link rel="author" title="Eric Willigers" href="mailto:ericwilligers@chromium.org">
|
|
<link rel="help" href="https://drafts.csswg.org/css-ui-3/#cursor">
|
|
<meta name="assert" content="cursor supports only the grammar.">
|
|
<script src="/resources/testharness.js"></script>
|
|
<script src="/resources/testharnessreport.js"></script>
|
|
<script src="/css/support/parsing-testcommon.js"></script>
|
|
</head>
|
|
<body>
|
|
<script>
|
|
test_invalid_value("cursor", "en-resize");
|
|
test_invalid_value("cursor", 'url("https://example.com/") alias');
|
|
test_invalid_value("cursor", '1 2 url("https://example.com/"), copy');
|
|
test_invalid_value("cursor", 'url("https://example.com/"), url("https://example.com/") 3, move');
|
|
|
|
test_invalid_value("cursor", 'url("https://example.com/") 1px 2px, copy');
|
|
test_invalid_value("cursor", 'url("https://example.com/"), url("https://example.com/") 3% 4%, move');
|
|
|
|
// The cursor property does not accept generated images, including inside
|
|
// light-dark().
|
|
test_invalid_value("cursor", "linear-gradient(red), pointer");
|
|
test_invalid_value("cursor", "light-dark(linear-gradient(red), none), pointer");
|
|
test_invalid_value("cursor", 'light-dark(url("https://example.com/"), linear-gradient(red)), pointer');
|
|
test_invalid_value("cursor", 'light-dark(radial-gradient(red), url("https://example.com/")), pointer');
|
|
</script>
|
|
</body>
|
|
</html>
|