Title: [233574] trunk/Source/WebCore
Revision
233574
Author
[email protected]
Date
2018-07-06 03:10:50 -0700 (Fri, 06 Jul 2018)

Log Message

[Crash] Illegal use of uninitialized std::optional value in WebCore::AnimationBase::updateStateMachine
https://bugs.webkit.org/show_bug.cgi?id=187382

Patch by Frederic Wang <[email protected]> on 2018-07-06
Reviewed by Carlos Garcia Campos.

WebCore::AnimationBase::updateStateMachine has two potential places where the use of an
uninitialized std:optional value is possible and one of them is hit when using Google drive.
Since that old animation code is going to be removed soon, we just quickly patch this issue
via value_or() so that we can restore the ASSERT added in bug 186536.

No new tests, code is going to be removed soon.

* page/animation/AnimationBase.cpp:
(WebCore::AnimationBase::updateStateMachine): Use value_or(0) to avoid potential crashes.

Modified Paths

Diff

Modified: trunk/Source/WebCore/ChangeLog (233573 => 233574)


--- trunk/Source/WebCore/ChangeLog	2018-07-06 07:59:53 UTC (rev 233573)
+++ trunk/Source/WebCore/ChangeLog	2018-07-06 10:10:50 UTC (rev 233574)
@@ -1,5 +1,22 @@
 2018-07-06  Frederic Wang  <[email protected]>
 
+        [Crash] Illegal use of uninitialized std::optional value in WebCore::AnimationBase::updateStateMachine
+        https://bugs.webkit.org/show_bug.cgi?id=187382
+
+        Reviewed by Carlos Garcia Campos.
+
+        WebCore::AnimationBase::updateStateMachine has two potential places where the use of an
+        uninitialized std:optional value is possible and one of them is hit when using Google drive.
+        Since that old animation code is going to be removed soon, we just quickly patch this issue
+        via value_or() so that we can restore the ASSERT added in bug 186536.
+
+        No new tests, code is going to be removed soon.
+
+        * page/animation/AnimationBase.cpp:
+        (WebCore::AnimationBase::updateStateMachine): Use value_or(0) to avoid potential crashes.
+
+2018-07-06  Frederic Wang  <[email protected]>
+
         Rename HTMLTreeBuilder::didCreateCustomOrCallbackElement
         https://bugs.webkit.org/show_bug.cgi?id=187317
 

Modified: trunk/Source/WebCore/page/animation/AnimationBase.cpp (233573 => 233574)


--- trunk/Source/WebCore/page/animation/AnimationBase.cpp	2018-07-06 07:59:53 UTC (rev 233573)
+++ trunk/Source/WebCore/page/animation/AnimationBase.cpp	2018-07-06 10:10:50 UTC (rev 233574)
@@ -379,7 +379,7 @@
             ASSERT(input == AnimationStateInput::PlayStateRunning);
             ASSERT(paused());
             // Update the times
-            m_startTime = m_startTime.value() + beginAnimationUpdateTime() - m_pauseTime.value_or(0);
+            m_startTime = m_startTime.value_or(0) + beginAnimationUpdateTime() - m_pauseTime.value_or(0);
             m_pauseTime = std::nullopt;
 
             // we were waiting for the start timer to fire, go back and wait again
@@ -411,7 +411,7 @@
 
                 // Update the times
                 if (m_animationState == AnimationState::PausedRun)
-                    m_startTime = m_startTime.value() + beginAnimationUpdateTime() - m_pauseTime.value_or(0);
+                    m_startTime = m_startTime.value_or(0) + beginAnimationUpdateTime() - m_pauseTime.value_or(0);
                 else
                     m_startTime = 0;
 
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to