⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 196965 in webkit


Ignore:
Timestamp:
Feb 22, 2016, 4:48:48 PM (11 years ago)
Author:
dbates@webkit.org
Message:

REGRESSION (r196892): Crash in DocumentLoader::startLoadingMainResource()
​https://bugs.webkit.org/show_bug.cgi?id=154563
<rdar://problem/24780678>

Reviewed by Alexey Proskuryakov.

Fixes an issue where the provisional loader may be deallocated when starting
a load. One example where this can occur is when cancelling the provisional load
as part of a form submission because the Content Security Policy of the page
blocks the submission (it violates the directive form-action).

This crash is covered by the test http/tests/security/contentSecurityPolicy/1.1/form-action-src-blocked.html.

  • loader/DocumentLoader.cpp:

(WebCore::DocumentLoader::startLoadingMainResource): Take a ref before calling
DocumentLoader::willSendRequest().

Location:
trunk/Source/WebCore
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/Source/WebCore/ChangeLog

    r196964 r196965  
     12016-02-22  Daniel Bates  <dabates@apple.com>
     2
     3        REGRESSION (r196892): Crash in DocumentLoader::startLoadingMainResource()
     4        https://bugs.webkit.org/show_bug.cgi?id=154563
     5        <rdar://problem/24780678>
     6
     7        Reviewed by Alexey Proskuryakov.
     8
     9        Fixes an issue where the provisional loader may be deallocated when starting
     10        a load. One example where this can occur is when cancelling the provisional load
     11        as part of a form submission because the Content Security Policy of the page
     12        blocks the submission (it violates the directive form-action).
     13
     14        This crash is covered by the test http/tests/security/contentSecurityPolicy/1.1/form-action-src-blocked.html.
     15
     16        * loader/DocumentLoader.cpp:
     17        (WebCore::DocumentLoader::startLoadingMainResource): Take a ref before calling
     18        DocumentLoader::willSendRequest().
     19
    1202016-02-16  Ada Chan  <adachan@apple.com>
    221
  • trunk/Source/WebCore/loader/DocumentLoader.cpp

    r196622 r196965  
    14651465    ASSERT(!timing().fetchStart());
    14661466    timing().markFetchStart();
     1467
     1468    Ref<DocumentLoader> protect(*this); // willSendRequest() may deallocate the provisional loader (which may be us) if it cancels the load.
    14671469    willSendRequest(m_request, ResourceResponse());
    14681470
Note: See TracChangeset for help on using the changeset viewer.