Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: f8e87320355d362f420704dfca481f26ac6517de
      
https://github.com/WebKit/WebKit/commit/f8e87320355d362f420704dfca481f26ac6517de
  Author: Claudio Saavedra <[email protected]>
  Date:   2026-10-02 (Fri, 02 Oct 2026)

  Changed paths:
    M Source/WebKit/UIProcess/API/gtk/DropTargetGtk3.cpp
    M Source/WebKit/UIProcess/API/gtk/DropTargetGtk4.cpp

  Log Message:
  -----------
  REGRESSION(308123@main, 309052@main, 309542@main): [GTK] Dropped markup and 
URI lists are decoded as Latin-1
https://bugs.webkit.org/show_bug.cgi?id=326075

Reviewed by Adrian Perez de Castro.

The unsafe buffer cleanups replaced String::fromUTF8(span) with String(span)
for the text/html, text/uri-list and _NETSCAPE_URL payloads received by the
drop targets. The span element type is unsigned char, so that selects the
Latin-1 constructor and any non-ASCII content in dropped HTML or file lists
is garbled.

309542@main also reinterprets a BOM-prefixed text/html payload as UTF-16 with
spanReinterpretCast(), which RELEASE_ASSERTs when the byte count is odd,
whereas the code it replaced truncated to whole code units. Sources that
append a trailing NUL byte to the selection trigger this.

Replace the hand-rolled byte order mark check with TextResourceDecoder, which
detects UTF-16 and UTF-8 byte order marks, defaults to UTF-8 and replaces a
dangling byte with U+FFFD. Restore String::fromUTF8() for the other two
payloads.

* Source/WebKit/UIProcess/API/gtk/DropTargetGtk3.cpp:
(WebKit::DropTarget::dataReceived):
* Source/WebKit/UIProcess/API/gtk/DropTargetGtk4.cpp:
(WebKit::DropTarget::accept):

Canonical link: https://commits.webkit.org/322589@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to