<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>129081</bug_id>
          
          <creation_ts>2014-02-19 21:36:58 -0800</creation_ts>
          <short_desc>ASSERT in FrameLoader::shouldInterruptLoadForXFrameOptions</short_desc>
          <delta_ts>2014-02-20 10:18:38 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebCore Misc.</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Pratik Solanki">psolanki</reporter>
          <assigned_to name="Pratik Solanki">psolanki</assigned_to>
          <cc>ap</cc>
    
    <cc>beidson</cc>
    
    <cc>commit-queue</cc>
    
    <cc>eric.carlson</cc>
    
    <cc>japhet</cc>
    
    <cc>psolanki</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>982662</commentid>
    <comment_count>0</comment_count>
    <who name="Pratik Solanki">psolanki</who>
    <bug_when>2014-02-19 21:36:58 -0800</bug_when>
    <thetext>Malformed servers that don&apos;t pass a value in X-Frame-Options can trigger this assert. e.g. on &lt;http://mweb.cbssports.com/ncaab/eye-on-college-basketball/24436548/night-court-marcus-foster-stars-xavier-and-iowa-get-key-wins&gt; there&apos;s a load of &lt;https://vine.co/v/MWmZ7L31emm/card&gt; in an iframe. The headers for that URL are

$ curl -I https://vine.co/v/MWmZ7L31emm/card
HTTP/1.1 200 OK
Cache-Control: max-age=1800
Content-Type: text/html; charset=utf-8
Date: Thu, 20 Feb 2014 05:36:30 GMT
Strict-Transport-Security: max-age=631138519
X-Content-Type-Options: nosniff
X-Frame-Options: 
X-XSS-Protection: 1; mode=block
Connection: keep-alive

The empty X-Frame-Options triggers the assert.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>982665</commentid>
    <comment_count>1</comment_count>
    <who name="Pratik Solanki">psolanki</who>
    <bug_when>2014-02-19 21:37:15 -0800</bug_when>
    <thetext>&lt;rdar://problem/16026440&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>982668</commentid>
    <comment_count>2</comment_count>
      <attachid>224705</attachid>
    <who name="Pratik Solanki">psolanki</who>
    <bug_when>2014-02-19 21:41:13 -0800</bug_when>
    <thetext>Created attachment 224705
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>982696</commentid>
    <comment_count>3</comment_count>
      <attachid>224705</attachid>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2014-02-19 23:03:57 -0800</bug_when>
    <thetext>Comment on attachment 224705
Patch

This breaks gcc build. I think that we need an ASSERT_NOT_REACHED() and return at the end.

/mnt/eflews/webkit/WebKit/Source/WebCore/loader/FrameLoader.cpp: In member function &apos;bool WebCore::FrameLoader::shouldInterruptLoadForXFrameOptions(const WTF::String&amp;, const WebCore::URL&amp;, long unsigned int)&apos;:
/mnt/eflews/webkit/WebKit/Source/WebCore/loader/FrameLoader.cpp:3074:1: error: control reaches end of non-void function [-Werror=return-type]
cc1plus: all warnings being treated as errors</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>982872</commentid>
    <comment_count>4</comment_count>
    <who name="Pratik Solanki">psolanki</who>
    <bug_when>2014-02-20 10:16:47 -0800</bug_when>
    <thetext>(In reply to comment #3)
&gt; (From update of attachment 224705 [details])
&gt; This breaks gcc build. I think that we need an ASSERT_NOT_REACHED() and return at the end.

Ok. Will add that and land the patch. Thanks for the review.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>982874</commentid>
    <comment_count>5</comment_count>
    <who name="Pratik Solanki">psolanki</who>
    <bug_when>2014-02-20 10:18:38 -0800</bug_when>
    <thetext>Committed r164435: &lt;http://trac.webkit.org/changeset/164435&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>224705</attachid>
            <date>2014-02-19 21:41:13 -0800</date>
            <delta_ts>2014-02-19 23:03:57 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-129081-20140219214112.patch</filename>
            <type>text/plain</type>
            <size>1644</size>
            <attacher name="Pratik Solanki">psolanki</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTY0MzU3CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggOGRjYWQ4MTA1ZDk0ZjMy
MmIzZGJlOTlhYjg0YWVkOTMyZjA0Zjc1NS4uMjQyZWRmYjE3NDIzMGI4MGExMDI1ODVkYzY2MWNk
MzJmZWIyYjhiMyAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDE2IEBACisyMDE0LTAyLTE5ICBQcmF0
aWsgU29sYW5raSAgPHBzb2xhbmtpQGFwcGxlLmNvbT4KKworICAgICAgICBBU1NFUlQgaW4gRnJh
bWVMb2FkZXI6OnNob3VsZEludGVycnVwdExvYWRGb3JYRnJhbWVPcHRpb25zCisgICAgICAgIGh0
dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0xMjkwODEKKyAgICAgICAgPHJk
YXI6Ly9wcm9ibGVtLzE2MDI2NDQwPgorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09Q
UyEpLgorCisgICAgICAgIERvIG5vdCBhc3NlcnQgaWYgdGhlIHNlcnZlciBzZW5kcyB1cyBhIG1h
bGZvcm1lZCBYLUZyYW1lLU9wdGlvbnMgaGVhZGVyLgorCisgICAgICAgICogbG9hZGVyL0ZyYW1l
TG9hZGVyLmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OkZyYW1lTG9hZGVyOjpzaG91bGRJbnRlcnJ1
cHRMb2FkRm9yWEZyYW1lT3B0aW9ucyk6CisKIDIwMTQtMDItMTggIERhbiBCZXJuc3RlaW4gIDxt
aXR6QGFwcGxlLmNvbT4KIAogICAgICAgICBQTEFURk9STShNQUMpIGlzIHRydWUgd2hlbiBidWls
ZGluZyBmb3IgaU9TCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9sb2FkZXIvRnJhbWVMb2Fk
ZXIuY3BwIGIvU291cmNlL1dlYkNvcmUvbG9hZGVyL0ZyYW1lTG9hZGVyLmNwcAppbmRleCA4MTgz
MGYwODQ5Yzc5YzYzNzkyYzlmYWJhMDY3OTEwNGRiZjFiMTZhLi43OGYwMzQ2ZGEzNmZhMzg2ZmQ5
YTkyODA2Zjg3NzM5YjhlMTdmNTZlIDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViQ29yZS9sb2FkZXIv
RnJhbWVMb2FkZXIuY3BwCisrKyBiL1NvdXJjZS9XZWJDb3JlL2xvYWRlci9GcmFtZUxvYWRlci5j
cHAKQEAgLTMwNjgsOCArMzA2OCw3IEBAIGJvb2wgRnJhbWVMb2FkZXI6OnNob3VsZEludGVycnVw
dExvYWRGb3JYRnJhbWVPcHRpb25zKGNvbnN0IFN0cmluZyYgY29udGVudCwgY29uCiAgICAgY2Fz
ZSBYRnJhbWVPcHRpb25zSW52YWxpZDoKICAgICAgICAgbV9mcmFtZS5kb2N1bWVudCgpLT5hZGRD
b25zb2xlTWVzc2FnZShNZXNzYWdlU291cmNlOjpKUywgTWVzc2FnZUxldmVsOjpFcnJvciwgIklu
dmFsaWQgJ1gtRnJhbWUtT3B0aW9ucycgaGVhZGVyIGVuY291bnRlcmVkIHdoZW4gbG9hZGluZyAn
IiArIHVybC5zdHJpbmdDZW50ZXJFbGxpcHNpemVkVG9MZW5ndGgoKSArICInOiAnIiArIGNvbnRl
bnQgKyAiJyBpcyBub3QgYSByZWNvZ25pemVkIGRpcmVjdGl2ZS4gVGhlIGhlYWRlciB3aWxsIGJl
IGlnbm9yZWQuIiwgcmVxdWVzdElkZW50aWZpZXIpOwogICAgICAgICByZXR1cm4gZmFsc2U7Ci0g
ICAgZGVmYXVsdDoKLSAgICAgICAgQVNTRVJUX05PVF9SRUFDSEVEKCk7CisgICAgY2FzZSBYRnJh
bWVPcHRpb25zTm9uZToKICAgICAgICAgcmV0dXJuIGZhbHNlOwogICAgIH0KIH0K
</data>
<flag name="review"
          id="248814"
          type_id="1"
          status="+"
          setter="ap"
    />
    <flag name="commit-queue"
          id="248815"
          type_id="3"
          status="-"
          setter="ap"
    />
          </attachment>
      

    </bug>

</bugzilla>