Visitar URL original
Null dereference in CSSParser::parsePageSelector() when inserting an @page rule into a detached CSSGroupingRule by Ahmad-S792 · Pull Request #76295 · WebKit/WebKit · GitHub
Skip to content

Null dereference in CSSParser::parsePageSelector() when inserting an @page rule into a detached CSSGroupingRule - #76295

Merged
webkit-commit-queue merged 1 commit into
WebKit:mainfrom
Ahmad-S792:eng/Null-dereference-in-CSSParser-parsePageSelector-when-inserting-an-page-rule-into-a-detached-CSSGroupingRule
Oct 8, 2026
Merged

webkit-commit-queue merged 1 commit into
WebKit:mainfrom
Ahmad-S792:eng/Null-dereference-in-CSSParser-parsePageSelector-when-inserting-an-page-rule-into-a-detached-CSSGroupingRule

Conversation

@Ahmad-S792

@Ahmad-S792 Ahmad-S792 commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

cc88e18

Null dereference in CSSParser::parsePageSelector() when inserting an @page rule into a detached CSSGroupingRule
https://bugs.webkit.org/show_bug.cgi?id=326788
rdar://189494639

Reviewed by Tim Nguyen.

When a CSSGroupingRule has been removed from its style sheet, insertRule() passes a null
StyleSheetContents to CSSParser::parseRule(). @page is allowed at that level, so
parsePageSelector() runs, and for any @page prelude that has a type selector
(e.g. "@page foo {}") it dereferences styleSheet->defaultNamespace(), crashing.

Fall back to starAtom() when there is no style sheet, which is what
CSSSelectorParser::defaultNamespace() does and the default namespace of a
StyleSheetContents with no @namespace rule.

Test: imported/w3c/web-platform-tests/css/cssom/insertRule-page-detached-grouping-rule-crash.html

* LayoutTests/imported/w3c/web-platform-tests/css/cssom/insertRule-page-detached-grouping-rule-crash.html: Added.
* Source/WebCore/css/parser/CSSParser.cpp:
(WebCore::CSSParser::parsePageSelector):

Canonical link: https://commits.webkit.org/323133@main

ad5f74c

Misc iOS, visionOS, tvOS & watchOS macOS Linux Windows Apple Internal
✅ 🧪 style ✅ 🛠 ios ✅ 🛠 mac ✅ 🛠 wpe   🛠 win ✅ 🛠 ios-apple
✅ 🧪 bindings ✅ 🛠 ios-sim ✅ 🛠 mac-AS-debug ✅ 🧪 wpe-wk2   🧪 win-tests ✅ 🛠 mac-apple
✅ 🧪 webkitperl ✅ 🧪 ios-wk2 ✅ 🧪 api-mac ✅ 🧪 api-wpe ✅ 🛠 vision-apple
✅ 🧪 ios-wk2-wpt   🧪 api-mac-debug
  🧪 api-ios ✅ 🧪 mac-wk2 ✅ 🛠 gtk3-gcc
✅ 🛠 ios-safer-cpp ✅ 🧪 mac-AS-debug-wk2 ✅ 🛠 gtk
✅ 🛠 vision ✅ 🧪 mac-wk2-stress ✅ 🧪 gtk-wk2
✅ 🛠 🧪 merge ✅ 🛠 vision-sim   🧪 mac-intel-wk2 ✅ 🧪 api-gtk
✅ 🧪 vision-wk2 ✅ 🛠 mac-safer-cpp ✅ 🛠 playstation
✅ 🛠 tv ✅ 🧪 mac-site-isolation
✅ 🛠 tv-sim
  🛠 watch
✅ 🛠 watch-sim

@Ahmad-S792 Ahmad-S792 self-assigned this Oct 8, 2026
@Ahmad-S792 Ahmad-S792 added the CSS Cascading Style Sheets implementation label Oct 8, 2026
@Ahmad-S792
Ahmad-S792 marked this pull request as ready for review October 8, 2026 17:18
@Ahmad-S792
Ahmad-S792 requested review from anttijk, nt1m and weinig and removed request for nt1m October 8, 2026 17:18
@Ahmad-S792 Ahmad-S792 added the merge-queue Applied to send a pull request to merge-queue label Oct 8, 2026
…page rule into a detached CSSGroupingRule

https://bugs.webkit.org/show_bug.cgi?id=326788
rdar://189494639

Reviewed by Tim Nguyen.

When a CSSGroupingRule has been removed from its style sheet, insertRule() passes a null
StyleSheetContents to CSSParser::parseRule(). @page is allowed at that level, so
parsePageSelector() runs, and for any @page prelude that has a type selector
(e.g. "@page foo {}") it dereferences styleSheet->defaultNamespace(), crashing.

Fall back to starAtom() when there is no style sheet, which is what
CSSSelectorParser::defaultNamespace() does and the default namespace of a
StyleSheetContents with no @namespace rule.

Test: imported/w3c/web-platform-tests/css/cssom/insertRule-page-detached-grouping-rule-crash.html

* LayoutTests/imported/w3c/web-platform-tests/css/cssom/insertRule-page-detached-grouping-rule-crash.html: Added.
* Source/WebCore/css/parser/CSSParser.cpp:
(WebCore::CSSParser::parsePageSelector):

Canonical link: https://commits.webkit.org/323133@main
@webkit-commit-queue
webkit-commit-queue force-pushed the eng/Null-dereference-in-CSSParser-parsePageSelector-when-inserting-an-page-rule-into-a-detached-CSSGroupingRule branch from ad5f74c to cc88e18 Compare October 8, 2026 17:37
@webkit-commit-queue

Copy link
Copy Markdown
Collaborator

Committed 323133@main (cc88e18): https://commits.webkit.org/323133@main

Reviewed commits have been landed. Closing PR #76295 and removing active labels.

@webkit-commit-queue
webkit-commit-queue merged commit cc88e18 into WebKit:main Oct 8, 2026
@webkit-commit-queue webkit-commit-queue removed the merge-queue Applied to send a pull request to merge-queue label Oct 8, 2026
@Ahmad-S792
Ahmad-S792 deleted the eng/Null-dereference-in-CSSParser-parsePageSelector-when-inserting-an-page-rule-into-a-detached-CSSGroupingRule branch October 8, 2026 18:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CSS Cascading Style Sheets implementation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants