Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 818e2e98284c21ef485f8665cb5566059495c40b
      
https://github.com/WebKit/WebKit/commit/818e2e98284c21ef485f8665cb5566059495c40b
  Author: Anne van Kesteren <[email protected]>
  Date:   2026-09-29 (Tue, 29 Sep 2026)

  Changed paths:
    A LayoutTests/accessibility/base-select-list-box-expected.txt
    A LayoutTests/accessibility/base-select-list-box.html
    M LayoutTests/platform/glib/TestExpectations
    M Source/WebCore/accessibility/AXObjectCache.cpp

  Log Message:
  -----------
  AX: base appearance list box crashes when walking the accessibility tree
https://bugs.webkit.org/show_bug.cgi?id=325605

Reviewed by Tyler Wilcock.

The options of a base appearance list box have boxes, so their accessibility 
objects are
created from their renderer, and createObjectFromRenderer() has no case for 
options. They
became generic objects whose parent is the slot they are assigned to, while the 
select, as
a list box, has its list items as its children. The slot's parent does not have 
it as a
child, which asserts in indexInSiblings().

Create an AccessibilityListBoxOption for an option or optgroup of a select that 
does not
use a menu list, as is done for options without a box. Its parent is the select 
and it has
no children, matching the list box. Its elementRect() already falls back to the 
renderer's
rect when the select is not a RenderListBox.

Test: accessibility/base-select-list-box.html
Canonical link: https://commits.webkit.org/322159@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to