<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>18237</bug_id>
          
          <creation_ts>2008-03-31 10:26:28 -0700</creation_ts>
          <short_desc>wrong unref of m_frame causes segfault</short_desc>
          <delta_ts>2017-03-11 10:55:52 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKitGTK</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>PC</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>UNCONFIRMED</bug_status>
          <resolution></resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>20403</blocked>
          <everconfirmed>0</everconfirmed>
          <reporter name="Salvatore De Paolis">iwkse</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>bugs-noreply</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>75937</commentid>
    <comment_count>0</comment_count>
    <who name="Salvatore De Paolis">iwkse</who>
    <bug_when>2008-03-31 10:26:28 -0700</bug_when>
    <thetext>m_frame is unref without checking if it&apos;s null and it causes a segfault</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>75938</commentid>
    <comment_count>1</comment_count>
      <attachid>20237</attachid>
    <who name="Salvatore De Paolis">iwkse</who>
    <bug_when>2008-03-31 10:27:33 -0700</bug_when>
    <thetext>Created attachment 20237
m_frame unref</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>75943</commentid>
    <comment_count>2</comment_count>
      <attachid>20237</attachid>
    <who name="Darin Adler">darin</who>
    <bug_when>2008-03-31 10:48:48 -0700</bug_when>
    <thetext>Comment on attachment 20237
m_frame unref

This looks wrong to me. I don&apos;t think this should be done in these detachedFromParent calls, and certainly not in both the (1) and (2) versions!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>75949</commentid>
    <comment_count>3</comment_count>
    <who name="Salvatore De Paolis">iwkse</who>
    <bug_when>2008-03-31 11:07:08 -0700</bug_when>
    <thetext>(In reply to comment #2)
&gt; (From update of attachment 20237 [edit])
&gt; This looks wrong to me. I don&apos;t think this should be done in these
&gt; detachedFromParent calls, and certainly not in both the (1) and (2) versions!
&gt; 
Actually the only one was the (4) and it segfaulted. Adding the check on m_frame fixed it. I thought it would work similar with the others but I did not find anybody to explain to me how it works with frames.
So keep it as WORKSFORME and feel free to update the patch.
</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>77221</commentid>
    <comment_count>4</comment_count>
      <attachid>20237</attachid>
    <who name="Mark Rowe (bdash)">mrowe</who>
    <bug_when>2008-04-10 17:47:47 -0700</bug_when>
    <thetext>Comment on attachment 20237
m_frame unref

r- based on Darin&apos;s comment.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>20237</attachid>
            <date>2008-03-31 10:27:33 -0700</date>
            <delta_ts>2010-06-10 15:57:37 -0700</delta_ts>
            <desc>m_frame unref</desc>
            <filename>m_frame.diff</filename>
            <type>text/plain</type>
            <size>1097</size>
            <attacher name="Salvatore De Paolis">iwkse</attacher>
            
              <data encoding="base64">SW5kZXg6IFdlYktpdC9ndGsvV2ViQ29yZVN1cHBvcnQvRnJhbWVMb2FkZXJDbGllbnRHdGsuY3Bw
Cj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT0KLS0tIFdlYktpdC9ndGsvV2ViQ29yZVN1cHBvcnQvRnJhbWVMb2FkZXJDbGll
bnRHdGsuY3BwCShyZXZpc2lvbiAzMTQ1NykKKysrIFdlYktpdC9ndGsvV2ViQ29yZVN1cHBvcnQv
RnJhbWVMb2FkZXJDbGllbnRHdGsuY3BwCSh3b3JraW5nIGNvcHkpCkBAIC00NDIsMjQgKzQ0Miwz
OCBAQAogCiB2b2lkIEZyYW1lTG9hZGVyQ2xpZW50OjpkZXRhY2hlZEZyb21QYXJlbnQxKCkKIHsK
LSAgICBub3RJbXBsZW1lbnRlZCgpOworICAgIEFTU0VSVChtX2ZyYW1lKTsKKyAgICBpZiAobV9m
cmFtZSkgeworICAgICAgICBnX29iamVjdF91bnJlZihtX2ZyYW1lKTsKKyAgICAgICAgbV9mcmFt
ZSA9IDA7CisgICAgfQogfQogCiB2b2lkIEZyYW1lTG9hZGVyQ2xpZW50OjpkZXRhY2hlZEZyb21Q
YXJlbnQyKCkKIHsKLSAgICBub3RJbXBsZW1lbnRlZCgpOworICAgIEFTU0VSVChtX2ZyYW1lKTsK
KyAgICBpZiAobV9mcmFtZSkgeworICAgICAgICBnX29iamVjdF91bnJlZihtX2ZyYW1lKTsKKyAg
ICAgICAgbV9mcmFtZSA9IDA7CisgICAgfQogfQogCiB2b2lkIEZyYW1lTG9hZGVyQ2xpZW50Ojpk
ZXRhY2hlZEZyb21QYXJlbnQzKCkKIHsKLSAgICBub3RJbXBsZW1lbnRlZCgpOworICAgIEFTU0VS
VChtX2ZyYW1lKTsKKyAgICBpZiAobV9mcmFtZSkgeworICAgICAgICBnX29iamVjdF91bnJlZiht
X2ZyYW1lKTsKKyAgICAgICAgbV9mcmFtZSA9IDA7CisgICAgfQogfQogCiB2b2lkIEZyYW1lTG9h
ZGVyQ2xpZW50OjpkZXRhY2hlZEZyb21QYXJlbnQ0KCkKIHsKICAgICBBU1NFUlQobV9mcmFtZSk7
Ci0gICAgZ19vYmplY3RfdW5yZWYobV9mcmFtZSk7Ci0gICAgbV9mcmFtZSA9IDA7CisgICAgaWYg
KG1fZnJhbWUpIHsKKyAgICAgICAgZ19vYmplY3RfdW5yZWYobV9mcmFtZSk7CisgICAgICAgIG1f
ZnJhbWUgPSAwOworICAgIH0KIH0KIAogdm9pZCBGcmFtZUxvYWRlckNsaWVudDo6bG9hZGVkRnJv
bUNhY2hlZFBhZ2UoKQo=
</data>
<flag name="review"
          id="8829"
          type_id="1"
          status="-"
          setter="mrowe"
    />
          </attachment>
      

    </bug>

</bugzilla>