⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 130611 in webkit


Ignore:
Timestamp:
Oct 7, 2012, 3:56:50 PM (14 years ago)
Author:
ggaren@apple.com
Message:

REGRESSION (r130584): Crashes in JSC::MarkedAllocator::allocateSlowCase, failing fast/dom/gc-dom-tree-lifetime.html
​https://bugs.webkit.org/show_bug.cgi?id=98612

Reviewed by Darin Adler.

Since DOM modification can happen outside of JS, calls into JS due to
DOM modification need to take the JS lock.

  • bindings/js/JSNodeCustom.cpp:

(WebCore::willCreatePossiblyOrphanedTreeByRemovalSlowCase): Take the JS
lock before doing a JS allocation, since this may be a JS entrypoint.

  • bindings/js/JSNodeCustom.h:

(WebCore::willCreatePossiblyOrphanedTreeByRemoval): Split out a slow case
to help the inliner.

Location:
trunk/Source/WebCore
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/Source/WebCore/ChangeLog

    r130610 r130611  
     12012-10-07  Geoffrey Garen  <ggaren@apple.com>
     2
     3        REGRESSION (r130584): Crashes in JSC::MarkedAllocator::allocateSlowCase, failing fast/dom/gc-dom-tree-lifetime.html
     4        https://bugs.webkit.org/show_bug.cgi?id=98612
     5
     6        Reviewed by Darin Adler.
     7
     8        Since DOM modification can happen outside of JS, calls into JS due to
     9        DOM modification need to take the JS lock.
     10
     11        * bindings/js/JSNodeCustom.cpp:
     12        (WebCore::willCreatePossiblyOrphanedTreeByRemovalSlowCase): Take the JS
     13        lock before doing a JS allocation, since this may be a JS entrypoint.
     14
     15        * bindings/js/JSNodeCustom.h:
     16        (WebCore::willCreatePossiblyOrphanedTreeByRemoval): Split out a slow case
     17        to help the inliner.
     18
    1192012-10-07  Nick Carter  <nick@chromium.org>
    220
  • trunk/Source/WebCore/bindings/js/JSNodeCustom.cpp

    r130584 r130611  
    277277}
    278278
     279void willCreatePossiblyOrphanedTreeByRemovalSlowCase(Node* root)
     280{
     281    ScriptState* scriptState = mainWorldScriptState(root->document()->frame());
     282    if (!scriptState)
     283        return;
     284
     285    JSLockHolder lock(scriptState);
     286    toJS(scriptState, static_cast<JSDOMGlobalObject*>(scriptState->lexicalGlobalObject()), root);
     287}
     288
    279289} // namespace WebCore
  • trunk/Source/WebCore/bindings/js/JSNodeCustom.h

    r130587 r130611  
    7474// reference to any node in the tree. To model the JavaScript DOM on top of
    7575// the C++ DOM, we ensure that the root of every tree has a JavaScript wrapper.
     76void willCreatePossiblyOrphanedTreeByRemovalSlowCase(Node* root);
    7677inline void willCreatePossiblyOrphanedTreeByRemoval(Node* root)
    7778{
    … …  
    8283        return;
    8384
    84     ScriptState* scriptState = mainWorldScriptState(root->document()->frame());
    85     if (!scriptState)
    86         return;
    87 
    88     toJS(scriptState, static_cast<JSDOMGlobalObject*>(scriptState->lexicalGlobalObject()), root);
     85    willCreatePossiblyOrphanedTreeByRemovalSlowCase(root);
    8986}
    9087
Note: See TracChangeset for help on using the changeset viewer.