<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>196479</bug_id>
          
          <creation_ts>2019-04-01 20:25:22 -0700</creation_ts>
          <short_desc>Nullptr crash in Document::open after calling policyChecker().stopCheck()</short_desc>
          <delta_ts>2019-04-01 23:44:47 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>DOM</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ryosuke Niwa">rniwa</reporter>
          <assigned_to name="Ryosuke Niwa">rniwa</assigned_to>
          <cc>achristensen</cc>
    
    <cc>cdumez</cc>
    
    <cc>esprehn+autocc</cc>
    
    <cc>ews-watchlist</cc>
    
    <cc>kangil.han</cc>
    
    <cc>koivisto</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1523202</commentid>
    <comment_count>0</comment_count>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2019-04-01 20:25:22 -0700</bug_when>
    <thetext>WebCore`WebCore::Document::open(WebCore::Document*) + 210 at Document.cpp:2647
       2643	        }
       2644	
       2645	        if (m_frame-&gt;loader().policyChecker().delegateIsDecidingNavigationPolicy())
       2646	            m_frame-&gt;loader().policyChecker().stopCheck();
    -&gt; 2647	        if (m_frame-&gt;loader().state() == FrameStateProvisional)
       2648	            m_frame-&gt;loader().stopAllLoaders();
       2649	    }
       2650	
       2651	    removeAllEventListeners();

We can hit a nullptr crash here because m_frame-&gt;loader().policyChecker().stopCheck() invokes m_willSubmitFormCompletionHandlers, and that could clear the frame, etc...

&lt;rdar://problem/48883397&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1523203</commentid>
    <comment_count>1</comment_count>
      <attachid>366464</attachid>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2019-04-01 20:27:37 -0700</bug_when>
    <thetext>Created attachment 366464
Fixes the bug</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1523237</commentid>
    <comment_count>2</comment_count>
    <who name="Ryosuke Niwa">rniwa</who>
    <bug_when>2019-04-01 23:44:47 -0700</bug_when>
    <thetext>Committed r243738: &lt;https://trac.webkit.org/changeset/243738&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>366464</attachid>
            <date>2019-04-01 20:27:37 -0700</date>
            <delta_ts>2019-04-01 23:40:38 -0700</delta_ts>
            <desc>Fixes the bug</desc>
            <filename>bug-196479-20190401202737.patch</filename>
            <type>text/plain</type>
            <size>1532</size>
            <attacher name="Ryosuke Niwa">rniwa</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJDb3JlL0NoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2Vi
Q29yZS9DaGFuZ2VMb2cJKHJldmlzaW9uIDI0MzczNSkKKysrIFNvdXJjZS9XZWJDb3JlL0NoYW5n
ZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE4IEBACisyMDE5LTA0LTAxICBSeW9zdWtl
IE5pd2EgIDxybml3YUB3ZWJraXQub3JnPgorCisgICAgICAgIE51bGxwdHIgY3Jhc2ggaW4gRG9j
dW1lbnQ6Om9wZW4gYWZ0ZXIgY2FsbGluZyBwb2xpY3lDaGVja2VyKCkuc3RvcENoZWNrKCkKKyAg
ICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTE5NjQ3OQorCisg
ICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIEFkZGVkIGEgbWlz
c2luZyBudWxscHRyIGNoZWNrIGluIERvY3VtZW50OjpvcGVuIGFmdGVyIGNhbGxpbmcgbV9mcmFt
ZS0+bG9hZGVyKCkucG9saWN5Q2hlY2tlcigpLnN0b3BDaGVjaygpCisgICAgICAgIHNpbmNlIGl0
IGludm9rZXMgbV93aWxsU3VibWl0Rm9ybUNvbXBsZXRpb25IYW5kbGVycyBpbiBXZWJLaXQyLCBh
bmQgdGhhdCBjb3VsZCBjbGVhciBtX2ZyYW1lLgorCisgICAgICAgIFVuZm9ydHVuYXRlbHksIHdl
IGRvbid0IGhhdmUgYW55IHJlcHJvZHVjaWJsZSB0ZXN0IGNhc2UuCisKKyAgICAgICAgKiBkb20v
RG9jdW1lbnQuY3BwOgorICAgICAgICAoV2ViQ29yZTo6RG9jdW1lbnQ6Om9wZW4pOgorCiAyMDE5
LTA0LTAxICBTaW1vbiBGcmFzZXIgIDxzaW1vbi5mcmFzZXJAYXBwbGUuY29tPgogCiAgICAgICAg
IFJlbW92ZSBzb21lIHVudXNlZCBpT1Mgc2Nyb2xsaW5nLXJlbGF0ZWQgY29kZSBpbiBGcmFtZQpJ
bmRleDogU291cmNlL1dlYkNvcmUvZG9tL0RvY3VtZW50LmNwcAo9PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3Vy
Y2UvV2ViQ29yZS9kb20vRG9jdW1lbnQuY3BwCShyZXZpc2lvbiAyNDM2NzMpCisrKyBTb3VyY2Uv
V2ViQ29yZS9kb20vRG9jdW1lbnQuY3BwCSh3b3JraW5nIGNvcHkpCkBAIC0yNzM4LDcgKzI3Mzgs
NyBAQCBFeGNlcHRpb25Pcjx2b2lkPiBEb2N1bWVudDo6b3BlbihEb2N1bWVuCiAKICAgICAgICAg
aWYgKG1fZnJhbWUtPmxvYWRlcigpLnBvbGljeUNoZWNrZXIoKS5kZWxlZ2F0ZUlzRGVjaWRpbmdO
YXZpZ2F0aW9uUG9saWN5KCkpCiAgICAgICAgICAgICBtX2ZyYW1lLT5sb2FkZXIoKS5wb2xpY3lD
aGVja2VyKCkuc3RvcENoZWNrKCk7Ci0gICAgICAgIGlmIChtX2ZyYW1lLT5sb2FkZXIoKS5zdGF0
ZSgpID09IEZyYW1lU3RhdGVQcm92aXNpb25hbCkKKyAgICAgICAgaWYgKG1fZnJhbWUgJiYgbV9m
cmFtZS0+bG9hZGVyKCkuc3RhdGUoKSA9PSBGcmFtZVN0YXRlUHJvdmlzaW9uYWwpCiAgICAgICAg
ICAgICBtX2ZyYW1lLT5sb2FkZXIoKS5zdG9wQWxsTG9hZGVycygpOwogICAgIH0KIAo=
</data>
<flag name="review"
          id="382846"
          type_id="1"
          status="+"
          setter="koivisto"
    />
          </attachment>
      

    </bug>

</bugzilla>