<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>154883</bug_id>
          
          <creation_ts>2016-03-01 15:31:51 -0800</creation_ts>
          <short_desc>[GTK] Plugin process crash in WebKit::NPObjectMessageReceiver::hasProperty</short_desc>
          <delta_ts>2016-10-28 06:23:39 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKitGTK</component>
          <version>Other</version>
          <rep_platform>PC</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>INVALID</resolution>
          
          <see_also>https://bugs.webkit.org/show_bug.cgi?id=154882</see_also>
    
    <see_also>https://bugzilla.redhat.com/show_bug.cgi?id=1290810</see_also>
    
    <see_also>https://bugs.webkit.org/show_bug.cgi?id=154888</see_also>
    
    <see_also>https://bugzilla.redhat.com/show_bug.cgi?id=1316102</see_also>
    
    <see_also>https://bugzilla.redhat.com/show_bug.cgi?id=1350512</see_also>
    
    <see_also>https://bugzilla.redhat.com/show_bug.cgi?id=1322731</see_also>
    
    <see_also>https://bugzilla.redhat.com/show_bug.cgi?id=1389269</see_also>
    
    <see_also>https://bugzilla.redhat.com/show_bug.cgi?id=1380136</see_also>
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>154891</blocked>
          <everconfirmed>0</everconfirmed>
          <reporter name="Michael Catanzaro">mcatanzaro</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>bugs-noreply</cc>
    
    <cc>cgarcia</cc>
    
    <cc>mcatanzaro</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1169593</commentid>
    <comment_count>0</comment_count>
    <who name="Michael Catanzaro">mcatanzaro</who>
    <bug_when>2016-03-01 15:31:51 -0800</bug_when>
    <thetext>Version-Release number of selected component:
webkitgtk4-2.10.4-1.fc23

Additional info:
reporter:       libreport-2.6.3
backtrace_rating: 4
cmdline:        /usr/libexec/webkit2gtk-4.0/WebKitPluginProcess 17 /usr/lib64/mozilla/plugins/libgnome-shell-browser-plugin.so
crash_function: WebKit::NPObjectMessageReceiver::hasProperty
executable:     /usr/libexec/webkit2gtk-4.0/WebKitPluginProcess
global_pid:     5739
kernel:         4.2.6-301.fc23.x86_64
runlevel:       N 5
type:           CCpp
uid:            1000

Truncated backtrace:
Thread no. 1 (10 frames)
 #0 WebKit::NPObjectMessageReceiver::hasProperty at /usr/src/debug/webkitgtk-2.10.4/Source/WebKit2/Shared/Plugins/NPObjectMessageReceiver.cpp:133
 #1 IPC::callMemberFunctionImpl&lt;WebKit::NPObjectMessageReceiver, void (WebKit::NPObjectMessageReceiver::*)(WebKit::NPIdentifierData const&amp;, bool&amp;), std::tuple&lt;WebKit::NPIdentifierData&gt;, 0ul, std::tuple&lt;bool&gt;, 0ul&gt;(WebKit::NPObjectMessageReceiver*, void (WebKit::NPObjectMessageReceiver::*)(WebKit::NPIdentifierData const&amp;, bool&amp;), std::tuple&lt;WebKit::NPIdentifierData&gt;&amp;&amp;, std::tuple&lt;bool&gt;&amp;, std::index_sequence&lt;0ul&gt;, std::index_sequence&lt;0ul&gt;) at /usr/src/debug/webkitgtk-2.10.4/Source/WebKit2/Platform/IPC/HandleMessage.h:30
 #2 IPC::callMemberFunction&lt;WebKit::NPObjectMessageReceiver, void (WebKit::NPObjectMessageReceiver::*)(WebKit::NPIdentifierData const&amp;, bool&amp;), std::tuple&lt;WebKit::NPIdentifierData&gt;, std::make_index_sequence&lt;1ul&gt;, std::tuple&lt;bool&gt;, std::make_index_sequence&lt;1ul&gt; &gt;(std::tuple&lt;WebKit::NPIdentifierData&gt;&amp;&amp;, std::tuple&lt;bool&gt;&amp;, WebKit::NPObjectMessageReceiver*, void (WebKit::NPObjectMessageReceiver::*)(WebKit::NPIdentifierData const&amp;, bool&amp;)) at /usr/src/debug/webkitgtk-2.10.4/Source/WebKit2/Platform/IPC/HandleMessage.h:36
 #3 IPC::handleMessage&lt;Messages::NPObjectMessageReceiver::RemoveProperty, WebKit::NPObjectMessageReceiver, void (WebKit::NPObjectMessageReceiver::*)(WebKit::NPIdentifierData const&amp;, bool&amp;)&gt; at /usr/src/debug/webkitgtk-2.10.4/Source/WebKit2/Platform/IPC/HandleMessage.h:105
 #4 WebKit::NPObjectMessageReceiver::didReceiveSyncNPObjectMessageReceiverMessage at /usr/src/debug/webkitgtk-2.10.4/x86_64-redhat-linux-gnu/DerivedSources/WebKit2/NPObjectMessageReceiverMessageReceiver.cpp:73
 #5 WebKit::NPRemoteObjectMap::didReceiveSyncMessage at /usr/src/debug/webkitgtk-2.10.4/Source/WebKit2/Shared/Plugins/NPRemoteObjectMap.cpp:226
 #6 WebKit::WebProcessConnection::didReceiveSyncMessage at /usr/src/debug/webkitgtk-2.10.4/Source/WebKit2/PluginProcess/WebProcessConnection.cpp:156
 #7 IPC::Connection::dispatchSyncMessage at /usr/src/debug/webkitgtk-2.10.4/Source/WebKit2/Platform/IPC/Connection.cpp:838
 #8 IPC::Connection::dispatchMessage at /usr/src/debug/webkitgtk-2.10.4/Source/WebKit2/Platform/IPC/Connection.cpp:901
 #9 IPC::Connection::SyncMessageState::dispatchMessages at /usr/src/debug/webkitgtk-2.10.4/Source/WebKit2/Platform/IPC/Connection.cpp:174

Another GNOME Shell browser plugin crash. This one was reported in December, so again, most likely with GNOME Shell 3.18.3. Possibly the same underlying issue as in bug #154882. Full backtrace downstream.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1169639</commentid>
    <comment_count>1</comment_count>
    <who name="Michael Catanzaro">mcatanzaro</who>
    <bug_when>2016-03-01 16:43:57 -0800</bug_when>
    <thetext>Another one the crash server thinks is fixed. Sorry for not checking this before reporting. :)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1172525</commentid>
    <comment_count>2</comment_count>
    <who name="Michael Catanzaro">mcatanzaro</who>
    <bug_when>2016-03-09 07:44:56 -0800</bug_when>
    <thetext>Got a report of this affecting 2.10.7.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1209480</commentid>
    <comment_count>3</comment_count>
    <who name="Michael Catanzaro">mcatanzaro</who>
    <bug_when>2016-07-09 14:18:13 -0700</bug_when>
    <thetext>(In reply to comment #2)
&gt; Got a report of this affecting 2.10.7.

Got a report of this affecting 2.12.3.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1214173</commentid>
    <comment_count>4</comment_count>
    <who name="Michael Catanzaro">mcatanzaro</who>
    <bug_when>2016-07-25 07:45:50 -0700</bug_when>
    <thetext>335 reports of this in Fedora, first report is last December. Probably another regression from GNOME Shell browser plugin changes.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1245571</commentid>
    <comment_count>5</comment_count>
    <who name="Carlos Garcia Campos">cgarcia</who>
    <bug_when>2016-10-28 06:23:39 -0700</bug_when>
    <thetext>This is a bug in the plugin, see the meta bug.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>