Title: [282493] releases/WebKitGTK/webkit-2.32/Source/WebCore
- Revision
- 282493
- Author
- [email protected]
- Date
- 2021-09-16 00:38:59 -0700 (Thu, 16 Sep 2021)
Log Message
Merge r275450 - PendingImageBitmap gets created on a stopped script execution context.
https://bugs.webkit.org/show_bug.cgi?id=223971
Reviewed by Youenn Fablet.
Don't create a PendingImageBitmap in PendingImageBitmap::fetch
if the associated script execution context had already been stoppped.
The new behavior matches of Chrome although it's technically incorrect.
Correcting it to match the spec & Firefox will refactor a larger fix around
how script execution context is used by the threaded loader.
* html/ImageBitmap.cpp:
(WebCore::PendingImageBitmap::fetch):
Modified Paths
Diff
Modified: releases/WebKitGTK/webkit-2.32/Source/WebCore/ChangeLog (282492 => 282493)
--- releases/WebKitGTK/webkit-2.32/Source/WebCore/ChangeLog 2021-09-16 07:35:49 UTC (rev 282492)
+++ releases/WebKitGTK/webkit-2.32/Source/WebCore/ChangeLog 2021-09-16 07:38:59 UTC (rev 282493)
@@ -1,3 +1,21 @@
+2021-04-02 Ryosuke Niwa <[email protected]>
+
+ PendingImageBitmap gets created on a stopped script execution context.
+ https://bugs.webkit.org/show_bug.cgi?id=223971
+
+ Reviewed by Youenn Fablet.
+
+ Don't create a PendingImageBitmap in PendingImageBitmap::fetch
+ if the associated script execution context had already been stoppped.
+
+ The new behavior matches of Chrome although it's technically incorrect.
+
+ Correcting it to match the spec & Firefox will refactor a larger fix around
+ how script execution context is used by the threaded loader.
+
+ * html/ImageBitmap.cpp:
+ (WebCore::PendingImageBitmap::fetch):
+
2021-03-31 Venky Dass <[email protected]>
Null pointer access crash in WebCore::makeBoundaryPoint(..)
Modified: releases/WebKitGTK/webkit-2.32/Source/WebCore/html/ImageBitmap.cpp (282492 => 282493)
--- releases/WebKitGTK/webkit-2.32/Source/WebCore/html/ImageBitmap.cpp 2021-09-16 07:35:49 UTC (rev 282492)
+++ releases/WebKitGTK/webkit-2.32/Source/WebCore/html/ImageBitmap.cpp 2021-09-16 07:38:59 UTC (rev 282493)
@@ -640,6 +640,8 @@
public:
static void fetch(ScriptExecutionContext& scriptExecutionContext, RefPtr<Blob>&& blob, ImageBitmapOptions&& options, Optional<IntRect> rect, ImageBitmap::Promise&& promise)
{
+ if (scriptExecutionContext.activeDOMObjectsAreStopped())
+ return;
auto pendingImageBitmap = new PendingImageBitmap(scriptExecutionContext, WTFMove(blob), WTFMove(options), WTFMove(rect), WTFMove(promise));
pendingImageBitmap->start(scriptExecutionContext);
}
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes