<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>120145</bug_id>
          
          <creation_ts>2013-08-21 17:54:18 -0700</creation_ts>
          <short_desc>Another null-deref under WebDragClient::startDrag</short_desc>
          <delta_ts>2013-08-21 17:59:08 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Tim Horton">thorton</reporter>
          <assigned_to name="Tim Horton">thorton</assigned_to>
          <cc>andersca</cc>
    
    <cc>sam</cc>
    
    <cc>simon.fraser</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>919696</commentid>
    <comment_count>0</comment_count>
    <who name="Tim Horton">thorton</who>
    <bug_when>2013-08-21 17:54:18 -0700</bug_when>
    <thetext>In http://trac.webkit.org/changeset/153511 I made convertImageToBitmap return null instead of dereferencing the null ShareableBitmap, but missed the place where we dereference the return value, and I missed that because I simultaneously fixed the one reproducible case of getting a null into this method in the first place :(

Add the second null-deref.

&lt;rdar://problem/14650652&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>919697</commentid>
    <comment_count>1</comment_count>
      <attachid>209316</attachid>
    <who name="Tim Horton">thorton</who>
    <bug_when>2013-08-21 17:55:51 -0700</bug_when>
    <thetext>Created attachment 209316
patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>919699</commentid>
    <comment_count>2</comment_count>
    <who name="Tim Horton">thorton</who>
    <bug_when>2013-08-21 17:59:08 -0700</bug_when>
    <thetext>http://trac.webkit.org/changeset/154433</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>209316</attachid>
            <date>2013-08-21 17:55:51 -0700</date>
            <delta_ts>2013-08-21 17:57:00 -0700</delta_ts>
            <desc>patch</desc>
            <filename>nullderef.diff</filename>
            <type>text/plain</type>
            <size>1535</size>
            <attacher name="Tim Horton">thorton</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJLaXQyL0NoYW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQyL0No
YW5nZUxvZwppbmRleCBiMjE2ZDJmLi5iYTFjMzE1IDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViS2l0
Mi9DaGFuZ2VMb2cKKysrIGIvU291cmNlL1dlYktpdDIvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTYg
QEAKKzIwMTMtMDgtMjEgIFRpbSBIb3J0b24gIDx0aW1vdGh5X2hvcnRvbkBhcHBsZS5jb20+CisK
KyAgICAgICAgQW5vdGhlciBudWxsLWRlcmVmIHVuZGVyIFdlYkRyYWdDbGllbnQ6OnN0YXJ0RHJh
ZworICAgICAgICBodHRwczovL2J1Z3Mud2Via2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9MTIwMTQ1
CisgICAgICAgIDxyZGFyOi8vcHJvYmxlbS8xNDY1MDY1Mj4KKworICAgICAgICBSZXZpZXdlZCBi
eSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBjb252ZXJ0SW1hZ2VUb0JpdG1hcCBjYW4gbGVn
aXRpbWF0ZWx5IHJldHVybiBudWxsLCBzbyBkb24ndCBkZXJlZmVyZW5jZSBpdC4KKworICAgICAg
ICAqIFdlYlByb2Nlc3MvV2ViQ29yZVN1cHBvcnQvbWFjL1dlYkRyYWdDbGllbnRNYWMubW06Cisg
ICAgICAgIChXZWJLaXQ6OldlYkRyYWdDbGllbnQ6OnN0YXJ0RHJhZyk6CisKIDIwMTMtMDgtMjEg
IEFsZXhleSBQcm9za3VyeWFrb3YgIDxhcEBhcHBsZS5jb20+CiAKICAgICAgICAgUkVHUkVTU0lP
TiAocjE0NTQ1OD8pOiBXZWJQcm9jZXNzIGRvZXNuJ3QgcmVzcGVjdCBVSSBwcm9jZXNzIGxvY2Fs
aXphdGlvbgpkaWZmIC0tZ2l0IGEvU291cmNlL1dlYktpdDIvV2ViUHJvY2Vzcy9XZWJDb3JlU3Vw
cG9ydC9tYWMvV2ViRHJhZ0NsaWVudE1hYy5tbSBiL1NvdXJjZS9XZWJLaXQyL1dlYlByb2Nlc3Mv
V2ViQ29yZVN1cHBvcnQvbWFjL1dlYkRyYWdDbGllbnRNYWMubW0KaW5kZXggMzI2NzhiOS4uMTQ3
ODc1NyAxMDA2NDQKLS0tIGEvU291cmNlL1dlYktpdDIvV2ViUHJvY2Vzcy9XZWJDb3JlU3VwcG9y
dC9tYWMvV2ViRHJhZ0NsaWVudE1hYy5tbQorKysgYi9Tb3VyY2UvV2ViS2l0Mi9XZWJQcm9jZXNz
L1dlYkNvcmVTdXBwb3J0L21hYy9XZWJEcmFnQ2xpZW50TWFjLm1tCkBAIC04Miw3ICs4Miw3IEBA
IHZvaWQgV2ViRHJhZ0NsaWVudDo6c3RhcnREcmFnKFJldGFpblB0cjxOU0ltYWdlPiBpbWFnZSwg
Y29uc3QgSW50UG9pbnQmIHBvaW50LCBjCiAgICAgYml0bWFwU2l6ZS5zY2FsZShmcmFtZS0+cGFn
ZSgpLT5kZXZpY2VTY2FsZUZhY3RvcigpKTsKICAgICBSZWZQdHI8U2hhcmVhYmxlQml0bWFwPiBi
aXRtYXAgPSBjb252ZXJ0SW1hZ2VUb0JpdG1hcChpbWFnZS5nZXQoKSwgYml0bWFwU2l6ZSk7CiAg
ICAgU2hhcmVhYmxlQml0bWFwOjpIYW5kbGUgaGFuZGxlOwotICAgIGlmICghYml0bWFwLT5jcmVh
dGVIYW5kbGUoaGFuZGxlKSkKKyAgICBpZiAoIWJpdG1hcCB8fCAhYml0bWFwLT5jcmVhdGVIYW5k
bGUoaGFuZGxlKSkKICAgICAgICAgcmV0dXJuOwogCiAgICAgLy8gRklYTUU6IFNlZW1zIHRoaXMg
bWVzc2FnZSBzaG91bGQgYmUgbmFtZWQgU3RhcnREcmFnLCBub3QgU2V0RHJhZ0ltYWdlLgo=
</data>
<flag name="review"
          id="231318"
          type_id="1"
          status="+"
          setter="simon.fraser"
    />
          </attachment>
      

    </bug>

</bugzilla>