Title: [112051] trunk
- Revision
- 112051
- Author
- [email protected]
- Date
- 2012-03-25 23:11:53 -0700 (Sun, 25 Mar 2012)
Log Message
Crash in ContainerNode::resumePostAttachCallbacks.
https://bugs.webkit.org/show_bug.cgi?id=82159
Reviewed by Hajime Morita.
Source/WebCore:
Test: plugins/object-onfocus-mutation-crash.html
* dom/ContainerNode.cpp:
(WebCore::ContainerNode::resumePostAttachCallbacks): dispatching post attach
callbacks when our attach depth is 1 can fire mutation events such as onfocus
which can blow away |this|. Need to protect it with a RefPtr.
* html/HTMLPlugInImageElement.cpp:
(WebCore::HTMLPlugInImageElement::attach): add calls to suspend attach callbacks
until the function completes.
LayoutTests:
* plugins/object-onfocus-mutation-crash-expected.txt: Added.
* plugins/object-onfocus-mutation-crash.html: Added.
Modified Paths
Added Paths
Diff
Modified: trunk/LayoutTests/ChangeLog (112050 => 112051)
--- trunk/LayoutTests/ChangeLog 2012-03-26 06:04:05 UTC (rev 112050)
+++ trunk/LayoutTests/ChangeLog 2012-03-26 06:11:53 UTC (rev 112051)
@@ -1,3 +1,13 @@
+2012-03-25 Abhishek Arya <[email protected]>
+
+ Crash in ContainerNode::resumePostAttachCallbacks.
+ https://bugs.webkit.org/show_bug.cgi?id=82159
+
+ Reviewed by Hajime Morita.
+
+ * plugins/object-onfocus-mutation-crash-expected.txt: Added.
+ * plugins/object-onfocus-mutation-crash.html: Added.
+
2012-03-25 Csaba Osztrogonác <[email protected]>
[Qt] Unreviewed gardening after r112022.
Added: trunk/LayoutTests/plugins/object-onfocus-mutation-crash-expected.txt (0 => 112051)
--- trunk/LayoutTests/plugins/object-onfocus-mutation-crash-expected.txt (rev 0)
+++ trunk/LayoutTests/plugins/object-onfocus-mutation-crash-expected.txt 2012-03-26 06:11:53 UTC (rev 112051)
@@ -0,0 +1 @@
+PASS. WebKit didn't crash.
Added: trunk/LayoutTests/plugins/object-onfocus-mutation-crash.html (0 => 112051)
--- trunk/LayoutTests/plugins/object-onfocus-mutation-crash.html (rev 0)
+++ trunk/LayoutTests/plugins/object-onfocus-mutation-crash.html 2012-03-26 06:11:53 UTC (rev 112051)
@@ -0,0 +1,24 @@
+<!DOCTYPE html>
+<html>
+<body>
+<script>
+if (window.layoutTestController) {
+ layoutTestController.dumpAsText();
+ layoutTestController.waitUntilDone();
+}
+
+function finish() {
+ if (window.layoutTestController)
+ layoutTestController.notifyDone();
+}
+
+function crash() {
+ document.body.innerHTML = "PASS. WebKit didn't crash.";
+ setTimeout("finish()", 0);
+}
+</script>
+<object data=""
+<input autofocus="" _onfocus_="crash()">
+</object>
+</body>
+</html>
Property changes on: trunk/LayoutTests/plugins/object-onfocus-mutation-crash.html
___________________________________________________________________
Added: svn:executable
Modified: trunk/Source/WebCore/ChangeLog (112050 => 112051)
--- trunk/Source/WebCore/ChangeLog 2012-03-26 06:04:05 UTC (rev 112050)
+++ trunk/Source/WebCore/ChangeLog 2012-03-26 06:11:53 UTC (rev 112051)
@@ -1,3 +1,20 @@
+2012-03-25 Abhishek Arya <[email protected]>
+
+ Crash in ContainerNode::resumePostAttachCallbacks.
+ https://bugs.webkit.org/show_bug.cgi?id=82159
+
+ Reviewed by Hajime Morita.
+
+ Test: plugins/object-onfocus-mutation-crash.html
+
+ * dom/ContainerNode.cpp:
+ (WebCore::ContainerNode::resumePostAttachCallbacks): dispatching post attach
+ callbacks when our attach depth is 1 can fire mutation events such as onfocus
+ which can blow away |this|. Need to protect it with a RefPtr.
+ * html/HTMLPlugInImageElement.cpp:
+ (WebCore::HTMLPlugInImageElement::attach): add calls to suspend attach callbacks
+ until the function completes.
+
2012-03-25 Dana Jansens <[email protected]>
[chromium] Layers with animating transforms should prepaint even if they are not visible yet
Modified: trunk/Source/WebCore/dom/ContainerNode.cpp (112050 => 112051)
--- trunk/Source/WebCore/dom/ContainerNode.cpp 2012-03-26 06:04:05 UTC (rev 112050)
+++ trunk/Source/WebCore/dom/ContainerNode.cpp 2012-03-26 06:11:53 UTC (rev 112051)
@@ -673,6 +673,8 @@
void ContainerNode::resumePostAttachCallbacks()
{
if (s_attachDepth == 1) {
+ RefPtr<ContainerNode> protect(this);
+
if (s_postAttachCallbackQueue)
dispatchPostAttachCallbacks();
if (s_shouldReEnableMemoryCacheCallsAfterAttach) {
Modified: trunk/Source/WebCore/html/HTMLPlugInImageElement.cpp (112050 => 112051)
--- trunk/Source/WebCore/html/HTMLPlugInImageElement.cpp 2012-03-26 06:04:05 UTC (rev 112050)
+++ trunk/Source/WebCore/html/HTMLPlugInImageElement.cpp 2012-03-26 06:11:53 UTC (rev 112051)
@@ -153,6 +153,8 @@
void HTMLPlugInImageElement::attach()
{
+ suspendPostAttachCallbacks();
+
bool isImage = isImageType();
if (!isImage)
@@ -165,6 +167,8 @@
m_imageLoader = adoptPtr(new HTMLImageLoader(this));
m_imageLoader->updateFromElement();
}
+
+ resumePostAttachCallbacks();
}
void HTMLPlugInImageElement::detach()
_______________________________________________
webkit-changes mailing list
[email protected]
http://lists.webkit.org/mailman/listinfo.cgi/webkit-changes