Changeset 130611 in webkit
- Timestamp:
- Oct 7, 2012, 3:56:50 PM (14 years ago)
- Location:
- trunk/Source/WebCore
- Files:
-
- 3 edited
-
ChangeLog (modified) (1 diff)
-
bindings/js/JSNodeCustom.cpp (modified) (1 diff)
-
bindings/js/JSNodeCustom.h (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/WebCore/ChangeLog
r130610 r130611 1 2012-10-07 Geoffrey Garen <ggaren@apple.com> 2 3 REGRESSION (r130584): Crashes in JSC::MarkedAllocator::allocateSlowCase, failing fast/dom/gc-dom-tree-lifetime.html 4 https://bugs.webkit.org/show_bug.cgi?id=98612 5 6 Reviewed by Darin Adler. 7 8 Since DOM modification can happen outside of JS, calls into JS due to 9 DOM modification need to take the JS lock. 10 11 * bindings/js/JSNodeCustom.cpp: 12 (WebCore::willCreatePossiblyOrphanedTreeByRemovalSlowCase): Take the JS 13 lock before doing a JS allocation, since this may be a JS entrypoint. 14 15 * bindings/js/JSNodeCustom.h: 16 (WebCore::willCreatePossiblyOrphanedTreeByRemoval): Split out a slow case 17 to help the inliner. 18 1 19 2012-10-07 Nick Carter <nick@chromium.org> 2 20 -
trunk/Source/WebCore/bindings/js/JSNodeCustom.cpp
r130584 r130611 277 277 } 278 278 279 void willCreatePossiblyOrphanedTreeByRemovalSlowCase(Node* root) 280 { 281 ScriptState* scriptState = mainWorldScriptState(root->document()->frame()); 282 if (!scriptState) 283 return; 284 285 JSLockHolder lock(scriptState); 286 toJS(scriptState, static_cast<JSDOMGlobalObject*>(scriptState->lexicalGlobalObject()), root); 287 } 288 279 289 } // namespace WebCore -
trunk/Source/WebCore/bindings/js/JSNodeCustom.h
r130587 r130611 74 74 // reference to any node in the tree. To model the JavaScript DOM on top of 75 75 // the C++ DOM, we ensure that the root of every tree has a JavaScript wrapper. 76 void willCreatePossiblyOrphanedTreeByRemovalSlowCase(Node* root); 76 77 inline void willCreatePossiblyOrphanedTreeByRemoval(Node* root) 77 78 { … … 82 83 return; 83 84 84 ScriptState* scriptState = mainWorldScriptState(root->document()->frame()); 85 if (!scriptState) 86 return; 87 88 toJS(scriptState, static_cast<JSDOMGlobalObject*>(scriptState->lexicalGlobalObject()), root); 85 willCreatePossiblyOrphanedTreeByRemovalSlowCase(root); 89 86 } 90 87
Note:
See TracChangeset
for help on using the changeset viewer.