What is going on in this page is: * We have two nested references + fallback, both with missing closing parens. * But the value actually ends with a closing paren, the rgb() function. So we fail to detect that the closing parens are missing, and we mess up the indices during substitution because we rely on the fallback end being the end of the var() reference minus 1. Properly tests for it by checking the block end against the outside-of-the-block start. If they're the same there was no closing paren. We could extend cssparser with this information maybe but for now this seems ok. UnquotedUrl I think we can leave as-is. Add two tests, once with a would be successful substitution that we get wrong right now, but this patch fixes, and the actually crashing test. I'm a bit surprised that no fuzzer has found this before tbh... Differential Revision: https://phabricator.services.mozilla.com/D281506
21 lines
926 B
HTML
21 lines
926 B
HTML
<!doctype html>
|
|
<title>Variable substitution with missing closing parenthesis</title>
|
|
<script src="/resources/testharness.js"></script>
|
|
<script src="/resources/testharnessreport.js"></script>
|
|
<link rel="help" href="https://bugzilla.mozilla.org/show_bug.cgi?id=2013337">
|
|
<link rel="help" href="https://drafts.csswg.org/css-variables/">
|
|
<link rel="author" title="Emilio Cobos Álvarez" href="mailto:emilio@crisal.io">
|
|
<link rel="author" title="Mozilla" href="https://mozilla.com">
|
|
<div
|
|
style="box-shadow:var(--token-62be83f1-0097-4872-b224-94c7b2aa11d6, 10px 10px 10px 10px rgb(245, 245, 245), 0px 0px 4px 2px var(--token-63fea906-5b5e-4ed0-9785-37e4c202cb5f, rgb(1, 255, 148)"
|
|
></div>
|
|
<script>
|
|
test(function() {
|
|
assert_equals(
|
|
getComputedStyle(document.querySelector("div")).boxShadow,
|
|
"rgb(245, 245, 245) 10px 10px 10px 10px, rgb(1, 255, 148) 0px 0px 4px 2px",
|
|
"Should substitute correctly"
|
|
);
|
|
});
|
|
</script>
|