Title: [295182] branches/safari-613-branch/Source/WebCore/animation/KeyframeEffect.cpp
- Revision
- 295182
- Author
- [email protected]
- Date
- 2022-06-02 23:45:24 -0700 (Thu, 02 Jun 2022)
Log Message
Cherry-pick 41769648c46b. rdar://problem/93513759
Need to keep the document alive in KeyframeEffect::processKeyframes()
https://bugs.webkit.org/show_bug.cgi?id=240677
<rdar://93513759>
Reviewed by Saam Barati.
Since the Document is used throughout KeyframeEffect::processKeyframes and it's provided
as a simple reference, we must ensure we keep it alive with a Ref since JS code in a custom
iterator for the keyframes object could cause it to be torn down.
* Source/WebCore/animation/KeyframeEffect.cpp:
(WebCore::KeyframeEffect::processKeyframes):
Canonical link: https://commits.webkit.org/250756@main
git-svn-id: https://svn.webkit.org/repository/webkit/trunk@294497 268f45cc-cd09-0410-ab3c-d52691b4dbfc
Modified Paths
Diff
Modified: branches/safari-613-branch/Source/WebCore/animation/KeyframeEffect.cpp (295181 => 295182)
--- branches/safari-613-branch/Source/WebCore/animation/KeyframeEffect.cpp 2022-06-03 06:45:22 UTC (rev 295181)
+++ branches/safari-613-branch/Source/WebCore/animation/KeyframeEffect.cpp 2022-06-03 06:45:24 UTC (rev 295182)
@@ -814,6 +814,8 @@
ExceptionOr<void> KeyframeEffect::processKeyframes(JSGlobalObject& lexicalGlobalObject, Strong<JSObject>&& keyframesInput)
{
+ Ref protectedDocument { document };
+
// 1. If object is null, return an empty sequence of keyframes.
if (!keyframesInput.get())
return { };
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes