Title: [295182] branches/safari-613-branch/Source/WebCore/animation/KeyframeEffect.cpp
Revision
295182
Author
[email protected]
Date
2022-06-02 23:45:24 -0700 (Thu, 02 Jun 2022)

Log Message

Cherry-pick 41769648c46b. rdar://problem/93513759

    Need to keep the document alive in KeyframeEffect::processKeyframes()
    https://bugs.webkit.org/show_bug.cgi?id=240677
    <rdar://93513759>

    Reviewed by Saam Barati.

    Since the Document is used throughout KeyframeEffect::processKeyframes and it's provided
    as a simple reference, we must ensure we keep it alive with a Ref since JS code in a custom
    iterator for the keyframes object could cause it to be torn down.

    * Source/WebCore/animation/KeyframeEffect.cpp:
    (WebCore::KeyframeEffect::processKeyframes):

    Canonical link: https://commits.webkit.org/250756@main
    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@294497 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Modified Paths

Diff

Modified: branches/safari-613-branch/Source/WebCore/animation/KeyframeEffect.cpp (295181 => 295182)


--- branches/safari-613-branch/Source/WebCore/animation/KeyframeEffect.cpp	2022-06-03 06:45:22 UTC (rev 295181)
+++ branches/safari-613-branch/Source/WebCore/animation/KeyframeEffect.cpp	2022-06-03 06:45:24 UTC (rev 295182)
@@ -814,6 +814,8 @@
 
 ExceptionOr<void> KeyframeEffect::processKeyframes(JSGlobalObject& lexicalGlobalObject, Strong<JSObject>&& keyframesInput)
 {
+    Ref protectedDocument { document };
+
     // 1. If object is null, return an empty sequence of keyframes.
     if (!keyframesInput.get())
         return { };
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to