Issue 3900: Chrome: Crash Report - Stack Signature:  
WebCore::Widget::setCursor(WebCore::Cursor const &)-4AC979
http://code.google.com/p/chromium/issues/detail?id=3900

Comment #2 by [EMAIL PROTECTED]:
Merge r4094 to the release branch:

Proposed fix for http://b/issue?id=1362948, which is a crash in the
rendererwhen we invoke the setCursor call on the parent view in
WebPluginImpl::handleEvent.
This crash occurs because the plugin is deleted in the context of a
mouse down event. This could occur by invoking a javascript function
via NPN_Evaluate. On return from the HandleEvent sync call we
attempt to retreive the parent frame, which returns NULL and hence
the crash.

The fix is to retreive the parent frameview at the start of the
WebPluginImpl::handleMouseEvent function and use it whereever
needed.

Added a unit test which deletes the plugin instance in a mousemove
event

Bug=1362948
TBR= [EMAIL PROTECTED]


Issue attribute updates:
        Status: Fixed

-- 
You received this message because you are listed in the owner
or CC fields of this issue, or because you starred this issue.
You may adjust your issue notification preferences at:
http://code.google.com/hosting/settings

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"Chromium-bugs" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/chromium-bugs?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to