⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 112051 in webkit


Ignore:
Timestamp:
Mar 25, 2012, 11:11:53 PM (15 years ago)
Author:
inferno@chromium.org
Message:

Crash in ContainerNode::resumePostAttachCallbacks.
​https://bugs.webkit.org/show_bug.cgi?id=82159

Reviewed by Hajime Morita.

Source/WebCore:

Test: plugins/object-onfocus-mutation-crash.html

  • dom/ContainerNode.cpp:

(WebCore::ContainerNode::resumePostAttachCallbacks): dispatching post attach
callbacks when our attach depth is 1 can fire mutation events such as onfocus
which can blow away |this|. Need to protect it with a RefPtr.

  • html/HTMLPlugInImageElement.cpp:

(WebCore::HTMLPlugInImageElement::attach): add calls to suspend attach callbacks
until the function completes.

LayoutTests:

  • plugins/object-onfocus-mutation-crash-expected.txt: Added.
  • plugins/object-onfocus-mutation-crash.html: Added.
Location:
trunk
Files:
2 added
4 edited

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/ChangeLog

    r112050 r112051  
     12012-03-25  Abhishek Arya  <inferno@chromium.org>
     2
     3        Crash in ContainerNode::resumePostAttachCallbacks.
     4        https://bugs.webkit.org/show_bug.cgi?id=82159
     5
     6        Reviewed by Hajime Morita.
     7
     8        * plugins/object-onfocus-mutation-crash-expected.txt: Added.
     9        * plugins/object-onfocus-mutation-crash.html: Added.
     10
    1112012-03-25  Csaba Osztrogonác  <ossy@webkit.org>
    212
  • trunk/Source/WebCore/ChangeLog

    r112049 r112051  
     12012-03-25  Abhishek Arya  <inferno@chromium.org>
     2
     3        Crash in ContainerNode::resumePostAttachCallbacks.
     4        https://bugs.webkit.org/show_bug.cgi?id=82159
     5
     6        Reviewed by Hajime Morita.
     7
     8        Test: plugins/object-onfocus-mutation-crash.html
     9
     10        * dom/ContainerNode.cpp:
     11        (WebCore::ContainerNode::resumePostAttachCallbacks): dispatching post attach
     12        callbacks when our attach depth is 1 can fire mutation events such as onfocus
     13        which can blow away |this|. Need to protect it with a RefPtr.
     14        * html/HTMLPlugInImageElement.cpp:
     15        (WebCore::HTMLPlugInImageElement::attach): add calls to suspend attach callbacks
     16        until the function completes.
     17
    1182012-03-25  Dana Jansens  <danakj@chromium.org>
    219
  • trunk/Source/WebCore/dom/ContainerNode.cpp

    r111925 r112051  
    674674{
    675675    if (s_attachDepth == 1) {
     676        RefPtr<ContainerNode> protect(this);
     677
    676678        if (s_postAttachCallbackQueue)
    677679            dispatchPostAttachCallbacks();
  • trunk/Source/WebCore/html/HTMLPlugInImageElement.cpp

    r106305 r112051  
    154154void HTMLPlugInImageElement::attach()
    155155{
     156    suspendPostAttachCallbacks();
     157
    156158    bool isImage = isImageType();
    157159   
    … …  
    166168        m_imageLoader->updateFromElement();
    167169    }
     170
     171    resumePostAttachCallbacks();
    168172}
    169173   
Note: See TracChangeset for help on using the changeset viewer.