⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 288506 in webkit


Ignore:
Timestamp:
Jan 24, 2022, 5:55:20 PM (5 years ago)
Author:
Russell Epstein
Message:

Cherry-pick r288039. rdar://problem/79220540

[iOS] Occasional crash under -[UITargetedPreview initWithView:parameters:target:] when focusing form controls
​https://bugs.webkit.org/show_bug.cgi?id=235248
rdar://79220540

Reviewed by Tim Horton and Aditya Keerthi.

Source/WebKit:

It's possible for -resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets: to return a nil snapshot
view in the case where a screen update has not been performed yet (among other scenarios). In the case where
UIKit returns nil when we're creating the targeted preview for the context menu when focusing a select element
or file input, we'll crash due to an Objective-C exception in the initializer of UITargetedPreview. Mitigate
this by falling back to an empty UIView after requesting the snapshot view to make our code robust against this
scenario.

Test: KeyboardInputTests.DoNotCrashWhenFocusingSelectWithoutViewSnapshot

  • UIProcess/ios/WKContentViewInteraction.mm: (createFallbackTargetedPreview):

Tools:

Add an API test that exercises the crash by forcing -resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:
to return nil via swizzling.

  • TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm: (TestWebKitAPI::nilResizableSnapshotViewFromRect): (TestWebKitAPI::TEST):

git-svn-id: ​https://svn.webkit.org/repository/webkit/trunk@288039 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Location:
branches/safari-613-branch
Files:
4 edited

Legend:

Unmodified
Added
Removed
  • branches/safari-613-branch/Source/WebKit/ChangeLog

    r288505 r288506  
     12022-01-24  Alan Coon  <alancoon@apple.com>
     2
     3        Cherry-pick r288039. rdar://problem/79220540
     4
     5    [iOS] Occasional crash under -[UITargetedPreview initWithView:parameters:target:] when focusing form controls
     6    https://bugs.webkit.org/show_bug.cgi?id=235248
     7    rdar://79220540
     8   
     9    Reviewed by Tim Horton and Aditya Keerthi.
     10   
     11    Source/WebKit:
     12   
     13    It's possible for `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:` to return a `nil` snapshot
     14    view in the case where a screen update has not been performed yet (among other scenarios). In the case where
     15    UIKit returns `nil` when we're creating the targeted preview for the context menu when focusing a select element
     16    or file input, we'll crash due to an Objective-C exception in the initializer of UITargetedPreview. Mitigate
     17    this by falling back to an empty UIView after requesting the snapshot view to make our code robust against this
     18    scenario.
     19   
     20    Test: KeyboardInputTests.DoNotCrashWhenFocusingSelectWithoutViewSnapshot
     21   
     22    * UIProcess/ios/WKContentViewInteraction.mm:
     23    (createFallbackTargetedPreview):
     24   
     25    Tools:
     26   
     27    Add an API test that exercises the crash by forcing `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:`
     28    to return nil via swizzling.
     29   
     30    * TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm:
     31    (TestWebKitAPI::nilResizableSnapshotViewFromRect):
     32    (TestWebKitAPI::TEST):
     33   
     34   
     35    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@288039 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     36
     37    2022-01-14  Wenson Hsieh  <wenson_hsieh@apple.com>
     38
     39            [iOS] Occasional crash under -[UITargetedPreview initWithView:parameters:target:] when focusing form controls
     40            https://bugs.webkit.org/show_bug.cgi?id=235248
     41            rdar://79220540
     42
     43            Reviewed by Tim Horton and Aditya Keerthi.
     44
     45            It's possible for `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:` to return a `nil` snapshot
     46            view in the case where a screen update has not been performed yet (among other scenarios). In the case where
     47            UIKit returns `nil` when we're creating the targeted preview for the context menu when focusing a select element
     48            or file input, we'll crash due to an Objective-C exception in the initializer of UITargetedPreview. Mitigate
     49            this by falling back to an empty UIView after requesting the snapshot view to make our code robust against this
     50            scenario.
     51
     52            Test: KeyboardInputTests.DoNotCrashWhenFocusingSelectWithoutViewSnapshot
     53
     54            * UIProcess/ios/WKContentViewInteraction.mm:
     55            (createFallbackTargetedPreview):
     56
    1572022-01-24  Alan Coon  <alancoon@apple.com>
    258
  • branches/safari-613-branch/Source/WebKit/UIProcess/ios/WKContentViewInteraction.mm

    r287737 r288506  
    86478647        [parameters setBackgroundColor:backgroundColor];
    86488648
    8649     UIView *snapshotView = [rootView resizableSnapshotViewFromRect:frameInRootViewCoordinates afterScreenUpdates:NO withCapInsets:UIEdgeInsetsZero];
     8649    RetainPtr snapshotView = [rootView resizableSnapshotViewFromRect:frameInRootViewCoordinates afterScreenUpdates:NO withCapInsets:UIEdgeInsetsZero];
     8650    if (!snapshotView)
     8651        snapshotView = adoptNS([UIView new]);
    86508652
    86518653    CGRect frameInContainerViewCoordinates = [rootView convertRect:frameInRootViewCoordinates toView:containerView];
    … …  
    86548656        return nil;
    86558657
    8656     snapshotView.frame = frameInContainerViewCoordinates;
     8658    [snapshotView setFrame:frameInContainerViewCoordinates];
    86578659
    86588660    CGPoint centerInContainerViewCoordinates = CGPointMake(CGRectGetMidX(frameInContainerViewCoordinates), CGRectGetMidY(frameInContainerViewCoordinates));
    86598661    auto target = adoptNS([[UIPreviewTarget alloc] initWithContainer:containerView center:centerInContainerViewCoordinates]);
    86608662
    8661     return adoptNS([[UITargetedPreview alloc] initWithView:snapshotView parameters:parameters.get() target:target.get()]);
     8663    return adoptNS([[UITargetedPreview alloc] initWithView:snapshotView.get() parameters:parameters.get() target:target.get()]);
    86628664}
    86638665
  • branches/safari-613-branch/Tools/ChangeLog

    r288501 r288506  
     12022-01-24  Alan Coon  <alancoon@apple.com>
     2
     3        Cherry-pick r288039. rdar://problem/79220540
     4
     5    [iOS] Occasional crash under -[UITargetedPreview initWithView:parameters:target:] when focusing form controls
     6    https://bugs.webkit.org/show_bug.cgi?id=235248
     7    rdar://79220540
     8   
     9    Reviewed by Tim Horton and Aditya Keerthi.
     10   
     11    Source/WebKit:
     12   
     13    It's possible for `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:` to return a `nil` snapshot
     14    view in the case where a screen update has not been performed yet (among other scenarios). In the case where
     15    UIKit returns `nil` when we're creating the targeted preview for the context menu when focusing a select element
     16    or file input, we'll crash due to an Objective-C exception in the initializer of UITargetedPreview. Mitigate
     17    this by falling back to an empty UIView after requesting the snapshot view to make our code robust against this
     18    scenario.
     19   
     20    Test: KeyboardInputTests.DoNotCrashWhenFocusingSelectWithoutViewSnapshot
     21   
     22    * UIProcess/ios/WKContentViewInteraction.mm:
     23    (createFallbackTargetedPreview):
     24   
     25    Tools:
     26   
     27    Add an API test that exercises the crash by forcing `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:`
     28    to return nil via swizzling.
     29   
     30    * TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm:
     31    (TestWebKitAPI::nilResizableSnapshotViewFromRect):
     32    (TestWebKitAPI::TEST):
     33   
     34   
     35    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@288039 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     36
     37    2022-01-14  Wenson Hsieh  <wenson_hsieh@apple.com>
     38
     39            [iOS] Occasional crash under -[UITargetedPreview initWithView:parameters:target:] when focusing form controls
     40            https://bugs.webkit.org/show_bug.cgi?id=235248
     41            rdar://79220540
     42
     43            Reviewed by Tim Horton and Aditya Keerthi.
     44
     45            Add an API test that exercises the crash by forcing `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:`
     46            to return nil via swizzling.
     47
     48            * TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm:
     49            (TestWebKitAPI::nilResizableSnapshotViewFromRect):
     50            (TestWebKitAPI::TEST):
     51
    1522022-01-24  Alan Coon  <alancoon@apple.com>
    253
  • branches/safari-613-branch/Tools/TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm

    r286552 r288506  
    827827}
    828828
     829static UIView * nilResizableSnapshotViewFromRect(id, SEL, CGRect, BOOL, UIEdgeInsets)
     830{
     831    return nil;
     832}
     833
     834TEST(KeyboardInputTests, DoNotCrashWhenFocusingSelectWithoutViewSnapshot)
     835{
     836    auto webView = adoptNS([[TestWKWebView alloc] initWithFrame:CGRectMake(0, 0, 320, 500)]);
     837    auto delegate = adoptNS([TestInputDelegate new]);
     838    [webView _setInputDelegate:delegate.get()];
     839    [delegate setFocusStartsInputSessionPolicyHandler:[](WKWebView *, id <_WKFocusedElementInfo>) {
     840        return _WKFocusStartsInputSessionPolicyAllow;
     841    }];
     842
     843    [webView synchronouslyLoadHTMLString:@"<select id='select'><option>foo</option><option>bar</option></select>"];
     844
     845    InstanceMethodSwizzler swizzler { UIView.class, @selector(resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:), reinterpret_cast<IMP>(nilResizableSnapshotViewFromRect) };
     846    [webView stringByEvaluatingJavaScript:@"select.focus()"];
     847    [webView waitForNextPresentationUpdate];
     848}
     849
    829850} // namespace TestWebKitAPI
    830851
Note: See TracChangeset for help on using the changeset viewer.