<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>23470</bug_id>
          
          <creation_ts>2009-01-21 20:52:17 -0800</creation_ts>
          <short_desc>Crash when page load occurs while processing scroll event with mallocscribble enabled</short_desc>
          <delta_ts>2009-01-22 08:59:44 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebCore Misc.</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Oliver Hunt">oliver</reporter>
          <assigned_to name="Oliver Hunt">oliver</assigned_to>
          
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>106571</commentid>
    <comment_count>0</comment_count>
    <who name="Oliver Hunt">oliver</who>
    <bug_when>2009-01-21 20:52:17 -0800</bug_when>
    <thetext>I spotted a crash that occurs when a page load occurs in the middle of processing a scroll event that has been propagated to a subframe that is destroyed by the page load.

Alas reproducing requires malloc scribble, and a timer driven load independent of webcore.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106572</commentid>
    <comment_count>1</comment_count>
      <attachid>26922</attachid>
    <who name="Oliver Hunt">oliver</who>
    <bug_when>2009-01-21 21:01:32 -0800</bug_when>
    <thetext>Created attachment 26922
Add a protector

Simple fix</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106573</commentid>
    <comment_count>2</comment_count>
      <attachid>26922</attachid>
    <who name="Dave Hyatt">hyatt</who>
    <bug_when>2009-01-21 21:12:26 -0800</bug_when>
    <thetext>Comment on attachment 26922
Add a protector

r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106600</commentid>
    <comment_count>3</comment_count>
    <who name="Oliver Hunt">oliver</who>
    <bug_when>2009-01-22 08:59:44 -0800</bug_when>
    <thetext>Committing to http://svn.webkit.org/repository/webkit/trunk ...
	M	WebCore/ChangeLog
	M	WebCore/page/EventHandler.cpp
Committed r40112
</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>26922</attachid>
            <date>2009-01-21 21:01:32 -0800</date>
            <delta_ts>2009-01-21 21:12:26 -0800</delta_ts>
            <desc>Add a protector</desc>
            <filename>bug23470.patch</filename>
            <type>text/plain</type>
            <size>1587</size>
            <attacher name="Oliver Hunt">oliver</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL1dlYkNvcmUvQ2hhbmdlTG9nIGIvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXgg
MDk5OTk5OS4uYzI4MjAwOCAxMDA2NDQKLS0tIGEvV2ViQ29yZS9DaGFuZ2VMb2cKKysrIGIvV2Vi
Q29yZS9DaGFuZ2VMb2cKQEAgLTEsMyArMSwxNyBAQAorMjAwOS0wMS0yMSAgT2xpdmVyIEh1bnQg
IDxvbGl2ZXJAYXBwbGUuY29tPgorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEp
LgorCisgICAgICAgIEJ1ZyAyMzQ3MDogQ3Jhc2ggd2hlbiBwYWdlIGxvYWQgb2NjdXJzIHdoaWxl
IHByb2Nlc3Npbmcgc2Nyb2xsIGV2ZW50IHdpdGggTWFsbG9jU2NyaWJibGUgZW5hYmxlZAorICAg
ICAgICA8aHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTIzNDcwPgorCisg
ICAgICAgIEFkZCBhIFJlZlB0ciBwcm90ZWN0b3IgdG8gaGFuZGxlV2hlZWxFdmVudCB0byBndWFy
ZCBhZ2FpbnN0IGRlc3RydWN0aW9uCisgICAgICAgIHdoaWxlIHByb2Nlc3NpbmcgdGhlIHNjcm9s
bCBldmVudC4gIEFsYXMgdGhlIGFic3VyZCBzZXQgb2YgY2lyY3Vtc3RhbmNlcworICAgICAgICBy
ZXF1aXJlZCB0byB0cmlnZ2VyIHRoaXMgZG8gbm90IGFwcGVhciB0byBiZSByZXByb2R1Y2libGUg
aW4gRFJULgorCisgICAgICAgICogcGFnZS9FdmVudEhhbmRsZXIuY3BwOgorICAgICAgICAoV2Vi
Q29yZTo6RXZlbnRIYW5kbGVyOjpoYW5kbGVXaGVlbEV2ZW50KToKKwogMjAwOS0wMS0yMSAgQW5k
ZXJzIENhcmxzc29uICA8YW5kZXJzY2FAYXBwbGUuY29tPgogCiAgICAgICAgIFJldmlld2VkIGJ5
IFNhbSBXZWluaWcuCmRpZmYgLS1naXQgYS9XZWJDb3JlL3BhZ2UvRXZlbnRIYW5kbGVyLmNwcCBi
L1dlYkNvcmUvcGFnZS9FdmVudEhhbmRsZXIuY3BwCmluZGV4IGQ3Y2QzYTEuLmI5MWMyYTcgMTAw
NjQ0Ci0tLSBhL1dlYkNvcmUvcGFnZS9FdmVudEhhbmRsZXIuY3BwCisrKyBiL1dlYkNvcmUvcGFn
ZS9FdmVudEhhbmRsZXIuY3BwCkBAIC0xLDUgKzEsNSBAQAogLyoKLSAqIENvcHlyaWdodCAoQykg
MjAwNiwgMjAwNywgMjAwOCBBcHBsZSBJbmMuIEFsbCByaWdodHMgcmVzZXJ2ZWQuCisgKiBDb3B5
cmlnaHQgKEMpIDIwMDYsIDIwMDcsIDIwMDgsIDIwMDkgQXBwbGUgSW5jLiBBbGwgcmlnaHRzIHJl
c2VydmVkLgogICogQ29weXJpZ2h0IChDKSAyMDA2IEFsZXhleSBQcm9za3VyeWFrb3YgKGFwQHdl
YmtpdC5vcmcpCiAgKgogICogUmVkaXN0cmlidXRpb24gYW5kIHVzZSBpbiBzb3VyY2UgYW5kIGJp
bmFyeSBmb3Jtcywgd2l0aCBvciB3aXRob3V0CkBAIC0xNTc5LDYgKzE1NzksOCBAQCBib29sIEV2
ZW50SGFuZGxlcjo6aGFuZGxlV2hlZWxFdmVudChQbGF0Zm9ybVdoZWVsRXZlbnQmIGUpCiAgICAg
UmVuZGVyT2JqZWN0KiBkb2NSZW5kZXJlciA9IGRvYy0+cmVuZGVyZXIoKTsKICAgICBpZiAoIWRv
Y1JlbmRlcmVyKQogICAgICAgICByZXR1cm4gZmFsc2U7CisgICAgCisgICAgUmVmUHRyPEZyYW1l
Vmlldz4gcHJvdGVjdG9yKG1fZnJhbWUtPnZpZXcoKSk7CiAKICAgICBJbnRQb2ludCB2UG9pbnQg
PSBtX2ZyYW1lLT52aWV3KCktPndpbmRvd1RvQ29udGVudHMoZS5wb3MoKSk7CiAK
</data>
<flag name="review"
          id="12891"
          type_id="1"
          status="+"
          setter="hyatt"
    />
          </attachment>
      

    </bug>

</bugzilla>