Files
sousa-gecko/testing/web-platform/tests/scroll-animations/scroll-timelines/setting-scroll-timeline-with-null-source-crash.html
T
Jonathan Watt cdd5d0888c Bug 2036130. Avoid crash in APZIsActiveForSource when the ScrollTimeline source is null. r=boris
The ScrollTimeline WebIDL constructor accepts a null source, so the
internal mSource.mElement can legitimately be null. This commit makes
the ScrollTimeline::State::APZIsActiveForSource() caller check whether
the State object has a source element before calling it.

Differential Revision: https://phabricator.services.mozilla.com/D300575
2026-05-21 10:01:38 +00:00

23 lines
901 B
HTML

<!DOCTYPE html>
<html class="reftest-wait">
<link rel="help" href="https://bugzilla.mozilla.org/show_bug.cgi?id=2036130">
<rect fill="red" id="svg-rect0" width="50"></rect>
<script>
document.addEventListener('DOMContentLoaded', () => {
const a = document.getElementById('svg-rect0').animate([{
transform: "perspective(500px) rotateX(45deg)",
}], { });
a.updatePlaybackRate(0);
a.timeline = new ScrollTimeline({source: document.getElementById('x')});
// The crash happens during a restyle that flushes layer changes for the
// animation. The reftest TYPE_LOAD harness doesn't tick rAFs after load, so
// without reftest-wait + two rAFs we finish the test before the restyle that
// would exercise the compositor path runs.
requestAnimationFrame(() => {
requestAnimationFrame(() => {
document.documentElement.classList.remove("reftest-wait");
});
});
});
</script>