Changeset 294684 in webkit
- Timestamp:
- May 23, 2022, 2:40:07 PM (4 years ago)
- Location:
- branches/safari-7613.3.1.1-branch/Source
- Files:
-
- 7 edited
-
WebCore/ChangeLog (modified) (1 diff)
-
WebCore/html/canvas/CanvasRenderingContext2DBase.cpp (modified) (1 diff)
-
WebCore/platform/graphics/BitmapImage.cpp (modified) (3 diffs)
-
WebCore/platform/graphics/BitmapImage.h (modified) (2 diffs)
-
WebCore/platform/graphics/ImageSource.cpp (modified) (3 diffs)
-
WebCore/platform/graphics/ImageSource.h (modified) (5 diffs)
-
WebKit/ChangeLog (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
branches/safari-7613.3.1.1-branch/Source/WebCore/ChangeLog
r294676 r294684 84 84 (WebCore::AccessibilityObject::accessibilityIsIgnored const): 85 85 Don't call ignoredFromModalPresence if we're in the midst of computing the current modal. 86 87 2022-05-23 Alan Coon <alancoon@apple.com>88 89 Cherry-pick r294280. rdar://problem/8798054390 91 REGRESSION(r249162): CanvasRenderingContext2DBase::drawImage() crashes if the image is animated and the first frame cannot be decoded92 https://bugs.webkit.org/show_bug.cgi?id=23911393 rdar://8798054394 95 Reviewed by Simon Fraser.96 97 Source/WebCore:98 99 CanvasRenderingContext2DBase::drawImage() needs to ensure the first frame100 of the animated image can be decoded correctly before creating the temporary101 static image. If the first frame can't be decoded, this function should return102 immediately. This matches the behavior of this function before r249162.103 104 The animated image decodes its frames asynchronously in a work queue. But105 the first frame has to be decoded synchronously in the main run loop. So106 to avoid running the image decoder in two different threads we are going107 to keep the first and the current frame cached when we receive a memory108 pressure warning. This should not increase the memory allocation of the109 animated image because the numbers of cached frames increases quickly and110 we keep all of them till a memory warning is received. But the memory111 pressure warning will be received a little bit more often. This depends112 on the memory size of the first frame.113 114 To make the code more robust, make ImageSource take a Ref<NativeImage>115 instead of taking a RefPtr<NativeImage>.116 117 * html/canvas/CanvasRenderingContext2DBase.cpp:118 (WebCore::CanvasRenderingContext2DBase::drawImage):119 * platform/graphics/BitmapImage.cpp:120 (WebCore::BitmapImage::BitmapImage):121 (WebCore::BitmapImage::destroyDecodedData):122 * platform/graphics/BitmapImage.h:123 * platform/graphics/ImageSource.cpp:124 (WebCore::ImageSource::ImageSource):125 (WebCore::ImageSource::destroyDecodedData):126 (WebCore::ImageSource::setNativeImage):127 * platform/graphics/ImageSource.h:128 (WebCore::ImageSource::create):129 (WebCore::ImageSource::isDecoderAvailable const):130 (WebCore::ImageSource::destroyAllDecodedData): Deleted.131 (WebCore::ImageSource::destroyAllDecodedDataExcludeFrame): Deleted.132 (WebCore::ImageSource::destroyDecodedDataBeforeFrame): Deleted.133 134 Source/WebKit:135 136 * GPUProcess/graphics/RemoteDisplayListRecorder.cpp:137 (WebKit::RemoteDisplayListRecorder::drawSystemImage):138 139 git-svn-id: https://svn.webkit.org/repository/webkit/trunk@294280 268f45cc-cd09-0410-ab3c-d52691b4dbfc140 141 2022-05-16 Said Abou-Hallawa <said@apple.com>142 143 REGRESSION(r249162): CanvasRenderingContext2DBase::drawImage() crashes if the image is animated and the first frame cannot be decoded144 https://bugs.webkit.org/show_bug.cgi?id=239113145 rdar://87980543146 147 Reviewed by Simon Fraser.148 149 CanvasRenderingContext2DBase::drawImage() needs to ensure the first frame150 of the animated image can be decoded correctly before creating the temporary151 static image. If the first frame can't be decoded, this function should return152 immediately. This matches the behavior of this function before r249162.153 154 The animated image decodes its frames asynchronously in a work queue. But155 the first frame has to be decoded synchronously in the main run loop. So156 to avoid running the image decoder in two different threads we are going157 to keep the first and the current frame cached when we receive a memory158 pressure warning. This should not increase the memory allocation of the159 animated image because the numbers of cached frames increases quickly and160 we keep all of them till a memory warning is received. But the memory161 pressure warning will be received a little bit more often. This depends162 on the memory size of the first frame.163 164 To make the code more robust, make ImageSource take a Ref<NativeImage>165 instead of taking a RefPtr<NativeImage>.166 167 * html/canvas/CanvasRenderingContext2DBase.cpp:168 (WebCore::CanvasRenderingContext2DBase::drawImage):169 * platform/graphics/BitmapImage.cpp:170 (WebCore::BitmapImage::BitmapImage):171 (WebCore::BitmapImage::destroyDecodedData):172 * platform/graphics/BitmapImage.h:173 * platform/graphics/ImageSource.cpp:174 (WebCore::ImageSource::ImageSource):175 (WebCore::ImageSource::destroyDecodedData):176 (WebCore::ImageSource::setNativeImage):177 * platform/graphics/ImageSource.h:178 (WebCore::ImageSource::create):179 (WebCore::ImageSource::isDecoderAvailable const):180 (WebCore::ImageSource::destroyAllDecodedData): Deleted.181 (WebCore::ImageSource::destroyAllDecodedDataExcludeFrame): Deleted.182 (WebCore::ImageSource::destroyDecodedDataBeforeFrame): Deleted.183 86 184 87 2022-05-23 Alan Coon <alancoon@apple.com> -
branches/safari-7613.3.1.1-branch/Source/WebCore/html/canvas/CanvasRenderingContext2DBase.cpp
r294675 r294684 1546 1546 if (image->isBitmapImage()) { 1547 1547 // Drawing an animated image to a canvas should draw the first frame (except for a few layout tests) 1548 if (image->isAnimated() && !document.settings().animatedImageDebugCanvasDrawingEnabled()) {1548 if (image->isAnimated() && !document.settings().animatedImageDebugCanvasDrawingEnabled()) 1549 1549 image = BitmapImage::create(image->nativeImage()); 1550 if (!image)1551 return { };1552 }1553 1550 downcast<BitmapImage>(*image).updateFromSettings(document.settings()); 1554 1551 } -
branches/safari-7613.3.1.1-branch/Source/WebCore/platform/graphics/BitmapImage.cpp
r294675 r294684 53 53 } 54 54 55 BitmapImage::BitmapImage(Ref<NativeImage>&& image) 56 : m_source(ImageSource::create(WTFMove(image))) 55 BitmapImage::BitmapImage(RefPtr<NativeImage>&& image, ImageObserver* observer) 56 : Image(observer) 57 , m_source(ImageSource::create(WTFMove(image))) 57 58 { 58 59 } … … 77 78 LOG(Images, "BitmapImage::%s - %p - url: %s", __FUNCTION__, this, sourceURL().string().utf8().data()); 78 79 79 if (!destroyAll) { 80 // Destroy all the frames between frame0 and m_currentFrame. 81 m_source->destroyDecodedData(1, m_currentFrame); 82 } else if (!canDestroyDecodedData()) { 83 // Destroy all the frames except frame0 and m_currentFrame. 84 m_source->destroyDecodedData(1, m_currentFrame); 85 m_source->destroyDecodedData(m_currentFrame + 1, frameCount()); 86 } else { 87 m_source->destroyDecodedData(0, frameCount()); 80 if (!destroyAll) 81 m_source->destroyDecodedDataBeforeFrame(m_currentFrame); 82 else if (!canDestroyDecodedData()) 83 m_source->destroyAllDecodedDataExcludeFrame(m_currentFrame); 84 else { 85 m_source->destroyAllDecodedData(); 88 86 m_currentFrameDecodingStatus = DecodingStatus::Invalid; 89 87 } … … 231 229 return ImageDrawResult::DidNothing; 232 230 231 233 232 auto srcRect = requestedSrcRect; 234 233 auto preferredSize = size(); -
branches/safari-7613.3.1.1-branch/Source/WebCore/platform/graphics/BitmapImage.h
r294675 r294684 54 54 class BitmapImage final : public Image { 55 55 public: 56 static Ref Ptr<BitmapImage> create(PlatformImagePtr&& platformImage)56 static Ref<BitmapImage> create(PlatformImagePtr&& platformImage, ImageObserver* observer = nullptr) 57 57 { 58 return create(NativeImage::create(WTFMove(platformImage)));58 return adoptRef(*new BitmapImage(NativeImage::create(WTFMove(platformImage)), observer)); 59 59 } 60 static Ref Ptr<BitmapImage> create(RefPtr<NativeImage>&& nativeImage)60 static Ref<BitmapImage> create(RefPtr<NativeImage>&& nativeImage, ImageObserver* observer = nullptr) 61 61 { 62 if (!nativeImage) 63 return nullptr; 64 return create(nativeImage.releaseNonNull()); 65 } 66 static Ref<BitmapImage> create(Ref<NativeImage>&& nativeImage) 67 { 68 return adoptRef(*new BitmapImage(WTFMove(nativeImage))); 62 return adoptRef(*new BitmapImage(WTFMove(nativeImage), observer)); 69 63 } 70 64 static Ref<BitmapImage> create(ImageObserver* observer = nullptr) … … 161 155 162 156 private: 163 WEBCORE_EXPORT BitmapImage(Ref <NativeImage>&&);157 WEBCORE_EXPORT BitmapImage(RefPtr<NativeImage>&&, ImageObserver* = nullptr); 164 158 WEBCORE_EXPORT BitmapImage(ImageObserver* = nullptr); 165 159 -
branches/safari-7613.3.1.1-branch/Source/WebCore/platform/graphics/ImageSource.cpp
r294675 r294684 45 45 } 46 46 47 ImageSource::ImageSource(Ref <NativeImage>&& nativeImage)47 ImageSource::ImageSource(RefPtr<NativeImage>&& nativeImage) 48 48 : m_runLoop(RunLoop::current()) 49 49 { … … 121 121 } 122 122 123 void ImageSource::destroyDecodedData(size_t begin, size_t end) 124 { 125 if (begin >= end) 126 return; 127 128 ASSERT(end <= m_frames.size()); 129 123 void ImageSource::destroyDecodedData(size_t frameCount, size_t excludeFrame) 124 { 130 125 unsigned decodedSize = 0; 131 126 132 for (size_t index = begin; index < end; ++index) 127 ASSERT(frameCount <= m_frames.size()); 128 129 for (size_t index = 0; index < frameCount; ++index) { 130 if (index == excludeFrame) 131 continue; 133 132 decodedSize += m_frames[index].clearImage(); 133 } 134 134 135 135 decodedSizeReset(decodedSize); … … 233 233 } 234 234 235 void ImageSource::setNativeImage(Ref <NativeImage>&& nativeImage)235 void ImageSource::setNativeImage(RefPtr<NativeImage>&& nativeImage) 236 236 { 237 237 ASSERT(m_frames.size() == 1); -
branches/safari-7613.3.1.1-branch/Source/WebCore/platform/graphics/ImageSource.h
r294675 r294684 52 52 } 53 53 54 static Ref<ImageSource> create(Ref <NativeImage>&& nativeImage)54 static Ref<ImageSource> create(RefPtr<NativeImage>&& nativeImage) 55 55 { 56 56 return adoptRef(*new ImageSource(WTFMove(nativeImage))); … … 63 63 64 64 unsigned decodedSize() const { return m_decodedSize; } 65 void destroyDecodedData(size_t begin, size_t end); 65 void destroyAllDecodedData() { destroyDecodedData(frameCount(), frameCount()); } 66 void destroyAllDecodedDataExcludeFrame(size_t excludeFrame) { destroyDecodedData(frameCount(), excludeFrame); } 67 void destroyDecodedDataBeforeFrame(size_t beforeFrame) { destroyDecodedData(beforeFrame, beforeFrame); } 66 68 void destroyIncompleteDecodedData(); 67 69 void clearFrameBufferCache(size_t beforeFrame); … … 127 129 private: 128 130 ImageSource(BitmapImage*, AlphaOption = AlphaOption::Premultiplied, GammaAndColorProfileOption = GammaAndColorProfileOption::Applied); 129 ImageSource(Ref <NativeImage>&&);131 ImageSource(RefPtr<NativeImage>&&); 130 132 131 133 enum class MetadataType { … … 152 154 bool ensureDecoderAvailable(FragmentedSharedBuffer* data); 153 155 bool isDecoderAvailable() const { return m_decoder; } 156 void destroyDecodedData(size_t frameCount, size_t excludeFrame); 154 157 void decodedSizeChanged(long long decodedSize); 155 158 void didDecodeProperties(unsigned decodedPropertiesSize); … … 159 162 void encodedDataStatusChanged(EncodedDataStatus); 160 163 161 void setNativeImage(Ref <NativeImage>&&);164 void setNativeImage(RefPtr<NativeImage>&&); 162 165 void cacheMetadataAtIndex(size_t, SubsamplingLevel, DecodingStatus = DecodingStatus::Invalid); 163 166 void cachePlatformImageAtIndex(PlatformImagePtr&&, size_t, SubsamplingLevel, const DecodingOptions&, DecodingStatus = DecodingStatus::Invalid); -
branches/safari-7613.3.1.1-branch/Source/WebKit/ChangeLog
r294675 r294684 1 2022-05-23 Alan Coon <alancoon@apple.com>2 3 Cherry-pick r294280. rdar://problem/879805434 5 REGRESSION(r249162): CanvasRenderingContext2DBase::drawImage() crashes if the image is animated and the first frame cannot be decoded6 https://bugs.webkit.org/show_bug.cgi?id=2391137 rdar://879805438 9 Reviewed by Simon Fraser.10 11 Source/WebCore:12 13 CanvasRenderingContext2DBase::drawImage() needs to ensure the first frame14 of the animated image can be decoded correctly before creating the temporary15 static image. If the first frame can't be decoded, this function should return16 immediately. This matches the behavior of this function before r249162.17 18 The animated image decodes its frames asynchronously in a work queue. But19 the first frame has to be decoded synchronously in the main run loop. So20 to avoid running the image decoder in two different threads we are going21 to keep the first and the current frame cached when we receive a memory22 pressure warning. This should not increase the memory allocation of the23 animated image because the numbers of cached frames increases quickly and24 we keep all of them till a memory warning is received. But the memory25 pressure warning will be received a little bit more often. This depends26 on the memory size of the first frame.27 28 To make the code more robust, make ImageSource take a Ref<NativeImage>29 instead of taking a RefPtr<NativeImage>.30 31 * html/canvas/CanvasRenderingContext2DBase.cpp:32 (WebCore::CanvasRenderingContext2DBase::drawImage):33 * platform/graphics/BitmapImage.cpp:34 (WebCore::BitmapImage::BitmapImage):35 (WebCore::BitmapImage::destroyDecodedData):36 * platform/graphics/BitmapImage.h:37 * platform/graphics/ImageSource.cpp:38 (WebCore::ImageSource::ImageSource):39 (WebCore::ImageSource::destroyDecodedData):40 (WebCore::ImageSource::setNativeImage):41 * platform/graphics/ImageSource.h:42 (WebCore::ImageSource::create):43 (WebCore::ImageSource::isDecoderAvailable const):44 (WebCore::ImageSource::destroyAllDecodedData): Deleted.45 (WebCore::ImageSource::destroyAllDecodedDataExcludeFrame): Deleted.46 (WebCore::ImageSource::destroyDecodedDataBeforeFrame): Deleted.47 48 Source/WebKit:49 50 * GPUProcess/graphics/RemoteDisplayListRecorder.cpp:51 (WebKit::RemoteDisplayListRecorder::drawSystemImage):52 53 git-svn-id: https://svn.webkit.org/repository/webkit/trunk@294280 268f45cc-cd09-0410-ab3c-d52691b4dbfc54 55 2022-05-16 Said Abou-Hallawa <said@apple.com>56 57 REGRESSION(r249162): CanvasRenderingContext2DBase::drawImage() crashes if the image is animated and the first frame cannot be decoded58 https://bugs.webkit.org/show_bug.cgi?id=23911359 rdar://8798054360 61 Reviewed by Simon Fraser.62 63 * GPUProcess/graphics/RemoteDisplayListRecorder.cpp:64 (WebKit::RemoteDisplayListRecorder::drawSystemImage):65 66 1 2022-05-02 Alan Coon <alancoon@apple.com> 67 2
Note:
See TracChangeset
for help on using the changeset viewer.