Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: 818e2e98284c21ef485f8665cb5566059495c40b
https://github.com/WebKit/WebKit/commit/818e2e98284c21ef485f8665cb5566059495c40b
Author: Anne van Kesteren <[email protected]>
Date: 2026-09-29 (Tue, 29 Sep 2026)
Changed paths:
A LayoutTests/accessibility/base-select-list-box-expected.txt
A LayoutTests/accessibility/base-select-list-box.html
M LayoutTests/platform/glib/TestExpectations
M Source/WebCore/accessibility/AXObjectCache.cpp
Log Message:
-----------
AX: base appearance list box crashes when walking the accessibility tree
https://bugs.webkit.org/show_bug.cgi?id=325605
Reviewed by Tyler Wilcock.
The options of a base appearance list box have boxes, so their accessibility
objects are
created from their renderer, and createObjectFromRenderer() has no case for
options. They
became generic objects whose parent is the slot they are assigned to, while the
select, as
a list box, has its list items as its children. The slot's parent does not have
it as a
child, which asserts in indexInSiblings().
Create an AccessibilityListBoxOption for an option or optgroup of a select that
does not
use a menu list, as is done for options without a box. Its parent is the select
and it has
no children, matching the list box. Its elementRect() already falls back to the
renderer's
rect when the select is not a RenderListBox.
Test: accessibility/base-select-list-box.html
Canonical link: https://commits.webkit.org/322159@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications