<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>129456</bug_id>
          
          <creation_ts>2014-02-27 15:52:59 -0800</creation_ts>
          <short_desc>Crash in RemoteLayerTreePropertyApplier::applyPropertiesToLayer</short_desc>
          <delta_ts>2014-02-27 15:59:04 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Tim Horton">thorton</reporter>
          <assigned_to name="Tim Horton">thorton</assigned_to>
          <cc>jonlee</cc>
    
    <cc>sam</cc>
    
    <cc>simon.fraser</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>985387</commentid>
    <comment_count>0</comment_count>
    <who name="Tim Horton">thorton</who>
    <bug_when>2014-02-27 15:52:59 -0800</bug_when>
    <thetext>&lt;rdar://problem/16182676&gt;

Seeing a crash in RemoteLayerTreePropertyApplier::applyPropertiesToLayer when going from having layer contents to not having layer contents. We&apos;re dereferencing the RemoteLayerBacking without checking if it exists, in the accelerated drawing codepath.

Also, this #if structure is disturbing (conditional control flow scares me), so rework it a bit.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>985392</commentid>
    <comment_count>1</comment_count>
      <attachid>225421</attachid>
    <who name="Tim Horton">thorton</who>
    <bug_when>2014-02-27 15:55:11 -0800</bug_when>
    <thetext>Created attachment 225421
patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>985395</commentid>
    <comment_count>2</comment_count>
      <attachid>225421</attachid>
    <who name="Tim Horton">thorton</who>
    <bug_when>2014-02-27 15:56:36 -0800</bug_when>
    <thetext>Comment on attachment 225421
patch

View in context: https://bugs.webkit.org/attachment.cgi?id=225421&amp;action=review

&gt; Source/WebKit2/ChangeLog:11
&gt; +        We were dereferencing the RemoteLayerBacking without checking if it exists,

+Store</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>985397</commentid>
    <comment_count>3</comment_count>
    <who name="Tim Horton">thorton</who>
    <bug_when>2014-02-27 15:59:04 -0800</bug_when>
    <thetext>http://trac.webkit.org/changeset/164840</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>225421</attachid>
            <date>2014-02-27 15:55:11 -0800</date>
            <delta_ts>2014-02-27 15:56:36 -0800</delta_ts>
            <desc>patch</desc>
            <filename>patch.diff</filename>
            <type>text/plain</type>
            <size>2385</size>
            <attacher name="Tim Horton">thorton</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJLaXQyL0NoYW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQyL0No
YW5nZUxvZwppbmRleCAxMWI1OWFhLi5kYjE1YmE1IDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViS2l0
Mi9DaGFuZ2VMb2cKKysrIGIvU291cmNlL1dlYktpdDIvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTcg
QEAKKzIwMTQtMDItMjcgIFRpbSBIb3J0b24gIDx0aW1vdGh5X2hvcnRvbkBhcHBsZS5jb20+CisK
KyAgICAgICAgQ3Jhc2ggaW4gUmVtb3RlTGF5ZXJUcmVlUHJvcGVydHlBcHBsaWVyOjphcHBseVBy
b3BlcnRpZXNUb0xheWVyCisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVn
LmNnaT9pZD0xMjk0NTYKKyAgICAgICAgPHJkYXI6Ly9wcm9ibGVtLzE2MTgyNjc2PgorCisgICAg
ICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgICogU2hhcmVkL21hYy9S
ZW1vdGVMYXllclRyZWVQcm9wZXJ0eUFwcGxpZXIubW06CisgICAgICAgIChXZWJLaXQ6OlJlbW90
ZUxheWVyVHJlZVByb3BlcnR5QXBwbGllcjo6YXBwbHlQcm9wZXJ0aWVzVG9MYXllcik6CisgICAg
ICAgIFdlIHdlcmUgZGVyZWZlcmVuY2luZyB0aGUgUmVtb3RlTGF5ZXJCYWNraW5nIHdpdGhvdXQg
Y2hlY2tpbmcgaWYgaXQgZXhpc3RzLAorICAgICAgICBpbiB0aGUgYWNjZWxlcmF0ZWQgZHJhd2lu
ZyBjb2RlcGF0aC4gVGhpcyBjYXNlIHdpbGwgb2NjdXIgaWYgYSBsYXllcgorICAgICAgICBwcmV2
aW91c2x5IGRyZXcgY29udGVudHMsIGJ1dCBub3cgZG9lcyBub3QuCisKIDIwMTQtMDItMjcgIEFu
ZGVycyBDYXJsc3NvbiAgPGFuZGVyc2NhQGFwcGxlLmNvbT4KIAogICAgICAgICBNYWtlIFdlYlBy
b2Nlc3NQcm94eTo6cGFnZXMoKSByZXR1cm4gYW4gSXRlcmF0b3JSYW5nZQpkaWZmIC0tZ2l0IGEv
U291cmNlL1dlYktpdDIvU2hhcmVkL21hYy9SZW1vdGVMYXllclRyZWVQcm9wZXJ0eUFwcGxpZXIu
bW0gYi9Tb3VyY2UvV2ViS2l0Mi9TaGFyZWQvbWFjL1JlbW90ZUxheWVyVHJlZVByb3BlcnR5QXBw
bGllci5tbQppbmRleCBhNDM0YmU2Li45ODVkMGMzIDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViS2l0
Mi9TaGFyZWQvbWFjL1JlbW90ZUxheWVyVHJlZVByb3BlcnR5QXBwbGllci5tbQorKysgYi9Tb3Vy
Y2UvV2ViS2l0Mi9TaGFyZWQvbWFjL1JlbW90ZUxheWVyVHJlZVByb3BlcnR5QXBwbGllci5tbQpA
QCAtMTY3LDE0ICsxNjcsMTggQEAgdm9pZCBSZW1vdGVMYXllclRyZWVQcm9wZXJ0eUFwcGxpZXI6
OmFwcGx5UHJvcGVydGllc1RvTGF5ZXIoQ0FMYXllciAqbGF5ZXIsIGNvbnMKICAgICAgICAgbGF5
ZXIudGltZU9mZnNldCA9IHByb3BlcnRpZXMudGltZU9mZnNldDsKIAogICAgIGlmIChwcm9wZXJ0
aWVzLmNoYW5nZWRQcm9wZXJ0aWVzICYgUmVtb3RlTGF5ZXJUcmVlVHJhbnNhY3Rpb246OkJhY2tp
bmdTdG9yZUNoYW5nZWQpIHsKKyAgICAgICAgaWYgKFJlbW90ZUxheWVyQmFja2luZ1N0b3JlKiBi
YWNraW5nU3RvcmUgPSBwcm9wZXJ0aWVzLmJhY2tpbmdTdG9yZS5nZXQoKSkgewogI2lmIFVTRShJ
T1NVUkZBQ0UpCi0gICAgICAgIGlmIChwcm9wZXJ0aWVzLmJhY2tpbmdTdG9yZS0+YWNjZWxlcmF0
ZXNEcmF3aW5nKCkpCi0gICAgICAgICAgICBsYXllci5jb250ZW50cyA9IChpZClwcm9wZXJ0aWVz
LmJhY2tpbmdTdG9yZS0+c3VyZmFjZSgpLmdldCgpOwotICAgICAgICBlbHNlCisgICAgICAgICAg
ICBpZiAoYmFja2luZ1N0b3JlLT5hY2NlbGVyYXRlc0RyYXdpbmcoKSkKKyAgICAgICAgICAgICAg
ICBsYXllci5jb250ZW50cyA9IChpZCliYWNraW5nU3RvcmUtPnN1cmZhY2UoKS5nZXQoKTsKKyAg
ICAgICAgICAgIGVsc2UKKyAgICAgICAgICAgICAgICBsYXllci5jb250ZW50cyA9IChpZCliYWNr
aW5nU3RvcmUtPmltYWdlKCkuZ2V0KCk7CiAjZWxzZQotICAgICAgICAgICAgQVNTRVJUKCFwcm9w
ZXJ0aWVzLmJhY2tpbmdTdG9yZSB8fCAhcHJvcGVydGllcy5iYWNraW5nU3RvcmUtPmFjY2VsZXJh
dGVzRHJhd2luZygpKTsKKyAgICAgICAgICAgIEFTU0VSVCghYmFja2luZ1N0b3JlLT5hY2NlbGVy
YXRlc0RyYXdpbmcoKSk7CisgICAgICAgICAgICBsYXllci5jb250ZW50cyA9IChpZCliYWNraW5n
U3RvcmUtPmltYWdlKCkuZ2V0KCk7CiAjZW5kaWYKLSAgICAgICAgbGF5ZXIuY29udGVudHMgPSBw
cm9wZXJ0aWVzLmJhY2tpbmdTdG9yZSA/IChpZClwcm9wZXJ0aWVzLmJhY2tpbmdTdG9yZS0+aW1h
Z2UoKS5nZXQoKSA6IG5pbDsKKyAgICAgICAgfSBlbHNlCisgICAgICAgICAgICBsYXllci5jb250
ZW50cyA9IG5pbDsKICAgICB9CiAKICAgICBpZiAocHJvcGVydGllcy5jaGFuZ2VkUHJvcGVydGll
cyAmIFJlbW90ZUxheWVyVHJlZVRyYW5zYWN0aW9uOjpGaWx0ZXJzQ2hhbmdlZCkK
</data>
<flag name="review"
          id="249557"
          type_id="1"
          status="+"
          setter="simon.fraser"
    />
          </attachment>
      

    </bug>

</bugzilla>