Title: [112051] trunk
Revision
112051
Author
[email protected]
Date
2012-03-25 23:11:53 -0700 (Sun, 25 Mar 2012)

Log Message

Crash in ContainerNode::resumePostAttachCallbacks.
https://bugs.webkit.org/show_bug.cgi?id=82159

Reviewed by Hajime Morita.

Source/WebCore:

Test: plugins/object-onfocus-mutation-crash.html

* dom/ContainerNode.cpp:
(WebCore::ContainerNode::resumePostAttachCallbacks): dispatching post attach
callbacks when our attach depth is 1 can fire mutation events such as onfocus
which can blow away |this|. Need to protect it with a RefPtr.
* html/HTMLPlugInImageElement.cpp:
(WebCore::HTMLPlugInImageElement::attach): add calls to suspend attach callbacks
until the function completes.

LayoutTests:

* plugins/object-onfocus-mutation-crash-expected.txt: Added.
* plugins/object-onfocus-mutation-crash.html: Added.

Modified Paths

Added Paths

Diff

Modified: trunk/LayoutTests/ChangeLog (112050 => 112051)


--- trunk/LayoutTests/ChangeLog	2012-03-26 06:04:05 UTC (rev 112050)
+++ trunk/LayoutTests/ChangeLog	2012-03-26 06:11:53 UTC (rev 112051)
@@ -1,3 +1,13 @@
+2012-03-25  Abhishek Arya  <[email protected]>
+
+        Crash in ContainerNode::resumePostAttachCallbacks.
+        https://bugs.webkit.org/show_bug.cgi?id=82159
+
+        Reviewed by Hajime Morita.
+
+        * plugins/object-onfocus-mutation-crash-expected.txt: Added.
+        * plugins/object-onfocus-mutation-crash.html: Added.
+
 2012-03-25  Csaba Osztrogonác  <[email protected]>
 
         [Qt] Unreviewed gardening after r112022.

Added: trunk/LayoutTests/plugins/object-onfocus-mutation-crash-expected.txt (0 => 112051)


--- trunk/LayoutTests/plugins/object-onfocus-mutation-crash-expected.txt	                        (rev 0)
+++ trunk/LayoutTests/plugins/object-onfocus-mutation-crash-expected.txt	2012-03-26 06:11:53 UTC (rev 112051)
@@ -0,0 +1 @@
+PASS. WebKit didn't crash.

Added: trunk/LayoutTests/plugins/object-onfocus-mutation-crash.html (0 => 112051)


--- trunk/LayoutTests/plugins/object-onfocus-mutation-crash.html	                        (rev 0)
+++ trunk/LayoutTests/plugins/object-onfocus-mutation-crash.html	2012-03-26 06:11:53 UTC (rev 112051)
@@ -0,0 +1,24 @@
+<!DOCTYPE html>
+<html>
+<body>
+<script>
+if (window.layoutTestController) {
+    layoutTestController.dumpAsText();
+    layoutTestController.waitUntilDone();
+}
+
+function finish() {
+    if (window.layoutTestController)
+        layoutTestController.notifyDone();
+}
+
+function crash() {
+    document.body.innerHTML = "PASS. WebKit didn't crash.";
+    setTimeout("finish()", 0);
+}
+</script>
+<object data=""
+<input autofocus="" _onfocus_="crash()">
+</object>
+</body>
+</html>
Property changes on: trunk/LayoutTests/plugins/object-onfocus-mutation-crash.html
___________________________________________________________________

Added: svn:executable

Modified: trunk/Source/WebCore/ChangeLog (112050 => 112051)


--- trunk/Source/WebCore/ChangeLog	2012-03-26 06:04:05 UTC (rev 112050)
+++ trunk/Source/WebCore/ChangeLog	2012-03-26 06:11:53 UTC (rev 112051)
@@ -1,3 +1,20 @@
+2012-03-25  Abhishek Arya  <[email protected]>
+
+        Crash in ContainerNode::resumePostAttachCallbacks.
+        https://bugs.webkit.org/show_bug.cgi?id=82159
+
+        Reviewed by Hajime Morita.
+
+        Test: plugins/object-onfocus-mutation-crash.html
+
+        * dom/ContainerNode.cpp:
+        (WebCore::ContainerNode::resumePostAttachCallbacks): dispatching post attach
+        callbacks when our attach depth is 1 can fire mutation events such as onfocus
+        which can blow away |this|. Need to protect it with a RefPtr.
+        * html/HTMLPlugInImageElement.cpp:
+        (WebCore::HTMLPlugInImageElement::attach): add calls to suspend attach callbacks
+        until the function completes.
+
 2012-03-25  Dana Jansens  <[email protected]>
 
         [chromium] Layers with animating transforms should prepaint even if they are not visible yet

Modified: trunk/Source/WebCore/dom/ContainerNode.cpp (112050 => 112051)


--- trunk/Source/WebCore/dom/ContainerNode.cpp	2012-03-26 06:04:05 UTC (rev 112050)
+++ trunk/Source/WebCore/dom/ContainerNode.cpp	2012-03-26 06:11:53 UTC (rev 112051)
@@ -673,6 +673,8 @@
 void ContainerNode::resumePostAttachCallbacks()
 {
     if (s_attachDepth == 1) {
+        RefPtr<ContainerNode> protect(this);
+
         if (s_postAttachCallbackQueue)
             dispatchPostAttachCallbacks();
         if (s_shouldReEnableMemoryCacheCallsAfterAttach) {

Modified: trunk/Source/WebCore/html/HTMLPlugInImageElement.cpp (112050 => 112051)


--- trunk/Source/WebCore/html/HTMLPlugInImageElement.cpp	2012-03-26 06:04:05 UTC (rev 112050)
+++ trunk/Source/WebCore/html/HTMLPlugInImageElement.cpp	2012-03-26 06:11:53 UTC (rev 112051)
@@ -153,6 +153,8 @@
 
 void HTMLPlugInImageElement::attach()
 {
+    suspendPostAttachCallbacks();
+
     bool isImage = isImageType();
     
     if (!isImage)
@@ -165,6 +167,8 @@
             m_imageLoader = adoptPtr(new HTMLImageLoader(this));
         m_imageLoader->updateFromElement();
     }
+
+    resumePostAttachCallbacks();
 }
     
 void HTMLPlugInImageElement::detach()
_______________________________________________
webkit-changes mailing list
[email protected]
http://lists.webkit.org/mailman/listinfo.cgi/webkit-changes

Reply via email to