Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: cb90ddfe0b239b3fbb641c42fa8cd6bece1ee164
https://github.com/WebKit/WebKit/commit/cb90ddfe0b239b3fbb641c42fa8cd6bece1ee164
Author: David Kilzer <[email protected]>
Date: 2026-10-02 (Fri, 02 Oct 2026)
Changed paths:
M Tools/TestWebKitAPI/Tests/WebKit/WKWebView/ios/KeyboardInputTestsIOS.mm
Log Message:
-----------
Copy the front key event before interpreting it in
WebPageProxy::interpretKeyEvent
<https://bugs.webkit.org/show_bug.cgi?id=320201>
<rdar://181632337>
Reviewed by Pascoe and Abrar Rahman Protyasha.
UPDATE: On `main`, commit 320030@main (70826d7c1dcb, Bug 322699,
rdar://186066986) already fixed this differently: `keyEventQueue` now
holds `Ref<NativeWebKeyboardEvent>`, so `protect(firstQueuedKeyEvent())`
keeps the event alive across the nested call, and
`NativeWebKeyboardEvent` can no longer be copied. Merge back only the
regression test.
`WebPageProxy::interpretKeyEvent()` passed a reference to the front
element of `keyEventQueue` -- a `Deque` that stores
`NativeWebKeyboardEvent`s by value -- into a nested synchronous
key-event interpretation call. That reference stays valid only while
the queue is not mutated, but the nested call runs UIKit text-input
handling that can re-enter `WebPageProxy` and mutate the queue:
`keyEventHandlingCompleted()` removes the front element via
`takeFirst()`, and `handleKeyboardEvent()` appends (which can
reallocate the backing store). Either one frees or relocates the
referenced event while the interpretation call is still on the stack.
Copy the front event onto the stack before the call so the object it
operates on has a lifetime independent of the queue. This follows the
existing precedent in `keyEventHandlingCompleted()`, which copies
`keyEventQueue.first()` into a local before passing it to
`sendKeyEvent()`. The real front element stays in the queue for
`keyEventHandlingCompleted()` to dequeue as before, and `nativeEvent()`
is retained by the interpretation path, so behavior is unchanged.
Add a regression test that focuses an input and, from within the nested
key-event interpretation, re-enters `-[WKWebView handleKeyEvent:]` to
append enough events to reallocate the queue while the front event is
being interpreted.
Test: Tools/TestWebKitAPI/Tests/WebKit/WKWebView/ios/KeyboardInputTestsIOS.mm
* Tools/TestWebKitAPI/Tests/WebKit/WKWebView/ios/KeyboardInputTestsIOS.mm:
(TestWebKitAPI::TEST(KeyboardInputTests,
ReentrantKeyEventDuringInterpretKeyEventDoesNotCrash)): Add.
Originally-landed-as: 316606.241@safari-7625-branch (8d6f7feff504).
rdar://187506664
Canonical link: https://commits.webkit.org/322503@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications