<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>123651</bug_id>
          
          <creation_ts>2013-11-01 17:55:05 -0700</creation_ts>
          <short_desc>Remote Layer Tree: Crashes allocating incredibly large backing store for tiled backing layers</short_desc>
          <delta_ts>2013-11-01 19:21:12 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Tim Horton">thorton</reporter>
          <assigned_to name="Tim Horton">thorton</assigned_to>
          <cc>andersca</cc>
    
    <cc>commit-queue</cc>
    
    <cc>simon.fraser</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>946126</commentid>
    <comment_count>0</comment_count>
    <who name="Tim Horton">thorton</who>
    <bug_when>2013-11-01 17:55:05 -0700</bug_when>
    <thetext>It&apos;s easy to crash on IE Flying Images if you increase the number of images a bit.

Tiled backing layers shouldn&apos;t have backing store themselves! But they do, because of a silly mistake in http://trac.webkit.org/changeset/158417... we can&apos;t dirty the whole layer if we have no existing front buffer if we have no paints, because that will lead to layers which were never setNeedsDisplay()&apos;d getting backing store. Added back an assertion that will catch this, too.

Probably we should strengthen the mechanism that causes never-setNeedsDisplay&apos;d layers from getting backing store.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>946127</commentid>
    <comment_count>1</comment_count>
      <attachid>215788</attachid>
    <who name="Tim Horton">thorton</who>
    <bug_when>2013-11-01 17:56:27 -0700</bug_when>
    <thetext>Created attachment 215788
patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>946165</commentid>
    <comment_count>2</comment_count>
      <attachid>215788</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2013-11-01 19:21:10 -0700</bug_when>
    <thetext>Comment on attachment 215788
patch

Clearing flags on attachment: 215788

Committed r158481: &lt;http://trac.webkit.org/changeset/158481&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>946166</commentid>
    <comment_count>3</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2013-11-01 19:21:12 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>215788</attachid>
            <date>2013-11-01 17:56:27 -0700</date>
            <delta_ts>2013-11-01 19:21:10 -0700</delta_ts>
            <desc>patch</desc>
            <filename>2.diff</filename>
            <type>text/plain</type>
            <size>2142</size>
            <attacher name="Tim Horton">thorton</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJLaXQyL0NoYW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQyL0No
YW5nZUxvZwppbmRleCBkNzNjNjE0Li44YTVkODk4IDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViS2l0
Mi9DaGFuZ2VMb2cKKysrIGIvU291cmNlL1dlYktpdDIvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTgg
QEAKKzIwMTMtMTEtMDEgIFRpbSBIb3J0b24gIDx0aW1vdGh5X2hvcnRvbkBhcHBsZS5jb20+CisK
KyAgICAgICAgUmVtb3RlIExheWVyIFRyZWU6IENyYXNoZXMgYWxsb2NhdGluZyBpbmNyZWRpYmx5
IGxhcmdlIGJhY2tpbmcgc3RvcmUgZm9yIHRpbGVkIGJhY2tpbmcgbGF5ZXJzCisgICAgICAgIGh0
dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0xMjM2NTEKKworICAgICAgICBS
ZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICAqIFNoYXJlZC9tYWMvUmVtb3Rl
TGF5ZXJCYWNraW5nU3RvcmUubW06CisgICAgICAgIChSZW1vdGVMYXllckJhY2tpbmdTdG9yZTo6
ZGlzcGxheSk6CisgICAgICAgIChSZW1vdGVMYXllckJhY2tpbmdTdG9yZTo6ZHJhd0luQ29udGV4
dCk6CisgICAgICAgIFdlIGNhbid0IGRpcnR5IHRoZSB3aG9sZSBsYXllciBpZiB3ZSBoYXZlIG5v
IGV4aXN0aW5nIGZyb250IGJ1ZmZlciBpZgorICAgICAgICB3ZSBoYXZlIG5vIHBhaW50cywgYmVj
YXVzZSB0aGF0IHdpbGwgbGVhZCB0byBsYXllcnMgd2hpY2ggd2VyZSBuZXZlcgorICAgICAgICBz
ZXROZWVkc0Rpc3BsYXkoKSdkIGdldHRpbmcgYmFja2luZyBzdG9yZS4gQWRkZWQgYmFjayBhbiBh
c3NlcnRpb24KKyAgICAgICAgdGhhdCB3aWxsIGNhdGNoIHRoaXMsIHRvby4KKwogMjAxMy0xMS0w
MSAgRGFuIEJlcm5zdGVpbiAgPG1pdHpAYXBwbGUuY29tPgogCiAgICAgICAgIFtDb2NvYV0gV0tP
YmplY3Qgc2VlbXMgdG8gYmUgaW5pdGlhbGl6aW5nIGl0cyB0YXJnZXQgaW4gYSB0aHJlYWQtc2Fm
ZSBtYW5uZXIsIGJ1dCByZWFsbHkgaXMgbm90CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0Mi9T
aGFyZWQvbWFjL1JlbW90ZUxheWVyQmFja2luZ1N0b3JlLm1tIGIvU291cmNlL1dlYktpdDIvU2hh
cmVkL21hYy9SZW1vdGVMYXllckJhY2tpbmdTdG9yZS5tbQppbmRleCA1NTMwNjY5Li4zZjNlMWE4
IDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViS2l0Mi9TaGFyZWQvbWFjL1JlbW90ZUxheWVyQmFja2lu
Z1N0b3JlLm1tCisrKyBiL1NvdXJjZS9XZWJLaXQyL1NoYXJlZC9tYWMvUmVtb3RlTGF5ZXJCYWNr
aW5nU3RvcmUubW0KQEAgLTE5MiwxMiArMTkyLDEyIEBAIGJvb2wgUmVtb3RlTGF5ZXJCYWNraW5n
U3RvcmU6OmRpc3BsYXkoKQogICAgICAgICByZXR1cm4gcHJldmlvdXNseURyZXdDb250ZW50czsK
ICAgICB9CiAKLSAgICBpZiAoIWhhc0Zyb250QnVmZmVyKCkpCi0gICAgICAgIG1fZGlydHlSZWdp
b24udW5pdGUoSW50UmVjdChJbnRQb2ludCgpLCBtX3NpemUpKTsKLQogICAgIGlmIChtX2RpcnR5
UmVnaW9uLmlzRW1wdHkoKSB8fCBtX3NpemUuaXNFbXB0eSgpKQogICAgICAgICByZXR1cm4gZmFs
c2U7CiAKKyAgICBpZiAoIWhhc0Zyb250QnVmZmVyKCkpCisgICAgICAgIG1fZGlydHlSZWdpb24u
dW5pdGUoSW50UmVjdChJbnRQb2ludCgpLCBtX3NpemUpKTsKKwogICAgIGlmIChtX2xheWVyLT5v
d25lcigpLT5wbGF0Zm9ybUNBTGF5ZXJTaG93UmVwYWludENvdW50ZXIobV9sYXllcikpIHsKICAg
ICAgICAgSW50UmVjdCBpbmRpY2F0b3JSZWN0ID0gbWFwVG9Db250ZW50Q29vcmRpbmF0ZXMoSW50
UmVjdCgwLCAwLCA1MiwgMjcpKTsKICAgICAgICAgbV9kaXJ0eVJlZ2lvbi51bml0ZShpbmRpY2F0
b3JSZWN0KTsKQEAgLTI4OSw2ICsyODksNyBAQCB2b2lkIFJlbW90ZUxheWVyQmFja2luZ1N0b3Jl
OjpkcmF3SW5Db250ZXh0KEdyYXBoaWNzQ29udGV4dCYgY29udGV4dCkKICAgICAgICAgY2FzZSBQ
bGF0Zm9ybUNBTGF5ZXI6OkxheWVyVHlwZVJvb3RMYXllcjoKICAgICAgICAgY2FzZSBQbGF0Zm9y
bUNBTGF5ZXI6OkxheWVyVHlwZUFWUGxheWVyTGF5ZXI6CiAgICAgICAgIGNhc2UgUGxhdGZvcm1D
QUxheWVyOjpMYXllclR5cGVDdXN0b206CisgICAgICAgICAgICBBU1NFUlRfTk9UX1JFQUNIRUQo
KTsKICAgICAgICAgICAgIGJyZWFrOwogICAgIH07CiAK
</data>

          </attachment>
      

    </bug>

</bugzilla>