<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>29313</bug_id>
          
          <creation_ts>2009-09-16 14:11:31 -0700</creation_ts>
          <short_desc>Fix hard-to-reproduce crash in HTMLTokenizer by avoiding a rare fastRealloc edge case</short_desc>
          <delta_ts>2009-10-19 09:18:31 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebCore Misc.</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>PC</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Dimitri Glazkov (Google)">dglazkov</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>ap</cc>
    
    <cc>commit-queue</cc>
    
    <cc>darin</cc>
    
    <cc>eric</cc>
    
    <cc>mbelshe</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>147615</commentid>
    <comment_count>0</comment_count>
    <who name="Dimitri Glazkov (Google)">dglazkov</who>
    <bug_when>2009-09-16 14:11:31 -0700</bug_when>
    <thetext>From bug 29026:

&quot;
.. I found a case in WebKit which attempts to
realloc(ptr, 0):
WTF::fastRealloc+0x10
WebCore::HTMLTokenizer::enlargeScriptBuffer+0x41
WebCore::HTMLTokenizer::parseComment+0x2a
WebCore::HTMLTokenizer::parseTag+0x1141
WebCore::HTMLTokenizer::write+0x414
WebCore::FrameLoader::write+0x36b
WebCore::FrameLoader::addData+0x12

To get here, we have to read data input off the socket which contains a partial
page ending with &quot;&lt;!--&quot;.  It&apos;s a little hard to reproduce.
&quot;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>147617</commentid>
    <comment_count>1</comment_count>
      <attachid>39660</attachid>
    <who name="Dimitri Glazkov (Google)">dglazkov</who>
    <bug_when>2009-09-16 14:14:25 -0700</bug_when>
    <thetext>Created attachment 39660
Fix HTMLTokenizer crash, v1.

 WebCore/ChangeLog              |   15 +++++++++++++++
 WebCore/html/HTMLTokenizer.cpp |    8 ++++++++
 2 files changed, 23 insertions(+), 0 deletions(-)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>147619</commentid>
    <comment_count>2</comment_count>
    <who name="Darin Adler">darin</who>
    <bug_when>2009-09-16 14:17:04 -0700</bug_when>
    <thetext>We have other test cases like this done with HTTP tests that deliver text slowly. Can we make a regression test case?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>147621</commentid>
    <comment_count>3</comment_count>
    <who name="Dimitri Glazkov (Google)">dglazkov</who>
    <bug_when>2009-09-16 14:20:11 -0700</bug_when>
    <thetext>(In reply to comment #2)
&gt; We have other test cases like this done with HTTP tests that deliver text
&gt; slowly. Can we make a regression test case?

Mike (the original finder of the problem), what do you think?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>147629</commentid>
    <comment_count>4</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2009-09-16 14:40:37 -0700</bug_when>
    <thetext>+    // If we allow fastRealloc(ptr, 0), it will call CRASH(). 

Given bug 29026, this may be too strong a statement. Will this change even be needed if bug 29026 is fixed the way we seem to have consensus on?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>152376</commentid>
    <comment_count>5</comment_count>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2009-10-05 11:07:42 -0700</bug_when>
    <thetext>Ping?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>155708</commentid>
    <comment_count>6</comment_count>
      <attachid>39660</attachid>
    <who name="Yong Li">yong.li.webkit</who>
    <bug_when>2009-10-19 08:52:28 -0700</bug_when>
    <thetext>Comment on attachment 39660
Fix HTMLTokenizer crash, v1.

Let commit bot land it</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>155728</commentid>
    <comment_count>7</comment_count>
      <attachid>39660</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2009-10-19 09:18:26 -0700</bug_when>
    <thetext>Comment on attachment 39660
Fix HTMLTokenizer crash, v1.

Clearing flags on attachment: 39660

Committed r49788: &lt;http://trac.webkit.org/changeset/49788&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>155729</commentid>
    <comment_count>8</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2009-10-19 09:18:31 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>39660</attachid>
            <date>2009-09-16 14:14:25 -0700</date>
            <delta_ts>2009-10-19 09:18:26 -0700</delta_ts>
            <desc>Fix HTMLTokenizer crash, v1.</desc>
            <filename>Fix-HTMLTokenizer-crash-v1..patch</filename>
            <type>text/plain</type>
            <size>1540</size>
            <attacher name="Dimitri Glazkov (Google)">dglazkov</attacher>
            
              <data encoding="base64">NTAxZjc4NjAyM2E0NjkzZmQ4NGM3ODQxYTZlMjk3NWUyOGNhMTkxYwpkaWZmIC0tZ2l0IGEvV2Vi
Q29yZS9DaGFuZ2VMb2cgYi9XZWJDb3JlL0NoYW5nZUxvZwppbmRleCBmYTNiYzk0Li5hY2I3ODQ1
IDEwMDY0NAotLS0gYS9XZWJDb3JlL0NoYW5nZUxvZworKysgYi9XZWJDb3JlL0NoYW5nZUxvZwpA
QCAtMSwzICsxLDE4IEBACisyMDA5LTA5LTEwICBEaW1pdHJpIEdsYXprb3YgIDxkZ2xhemtvdkBj
aHJvbWl1bS5vcmc+CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAg
ICAgICAgRml4IGhhcmQtdG8tcmVwcm9kdWNlIGNyYXNoIGluIEhUTUxUb2tlbml6ZXIgYnkgYXZv
aWRpbmcgYSByYXJlCisgICAgICAgIGZhc3RSZWFsbG9jIGVkZ2UgY2FzZS4KKyAgICAgICAgaHR0
cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTI5MzEzCisKKyAgICAgICAgTm8g
dGVzdCwgdGhlIGNyYXNoIHNob3dzIHVwIG9jY2FzaW9uYWxseSBpbiBjcmFzaCBkdW1wcywgd2Ug
d2VyZW4ndCBhYmxlCisgICAgICAgIHRvIHJlcHJvZHVjZSBpdCBsb2NhbGx5LgorCisgICAgICAg
ICogaHRtbC9IVE1MVG9rZW5pemVyLmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OkhUTUxUb2tlbml6
ZXI6OmVubGFyZ2VTY3JpcHRCdWZmZXIpOiBBZGRlZCBhbiBlYXJseSBleGl0IHRvCisgICAgICAg
ICAgICBhdm9pZCBjYWxsaW5nIGZhc3RSZWFsbG9jIHdpdGggdGhlIHNpemUgb2YgMC4KKwogMjAw
OS0wOS0xNiAgQ2Fyb2wgU3phYm8gIDxjYXJvbC5zemFib0Bub2tpYS5jb20+CiAKICAgICAgICAg
UmV2aWV3ZWQgYnkgQWxleGV5IFByb3NrdXJ5YWtvdi4KZGlmZiAtLWdpdCBhL1dlYkNvcmUvaHRt
bC9IVE1MVG9rZW5pemVyLmNwcCBiL1dlYkNvcmUvaHRtbC9IVE1MVG9rZW5pemVyLmNwcAppbmRl
eCA3MWZhYWMwLi41MWU3NTg0IDEwMDY0NAotLS0gYS9XZWJDb3JlL2h0bWwvSFRNTFRva2VuaXpl
ci5jcHAKKysrIGIvV2ViQ29yZS9odG1sL0hUTUxUb2tlbml6ZXIuY3BwCkBAIC0xOTgwLDYgKzE5
ODAsMTQgQEAgdm9pZCBIVE1MVG9rZW5pemVyOjplbmxhcmdlU2NyaXB0QnVmZmVyKGludCBsZW4p
CiAgICAgICAgIENSQVNIKCk7CiAKICAgICBpbnQgbmV3U2l6ZSA9IG1fc2NyaXB0Q29kZUNhcGFj
aXR5ICsgZGVsdGE7CisgICAgLy8gSWYgd2UgYWxsb3cgZmFzdFJlYWxsb2MocHRyLCAwKSwgaXQg
d2lsbCBjYWxsIENSQVNIKCkuIFdlIHJ1biBpbnRvIHRoaXMKKyAgICAvLyBjYXNlIGlmIHRoZSBI
VE1MIGJlaW5nIHBhcnNlZCBiZWdpbnMgd2l0aCAiPCEtLSIgYW5kIHRoZXJlJ3MgbW9yZSBkYXRh
CisgICAgLy8gY29taW5nLgorICAgIGlmICghbmV3U2l6ZSkgeworICAgICAgICBBU1NFUlQoIW1f
c2NyaXB0Q29kZSk7CisgICAgICAgIHJldHVybjsKKyAgICB9CisKICAgICBtX3NjcmlwdENvZGUg
PSBzdGF0aWNfY2FzdDxVQ2hhcio+KGZhc3RSZWFsbG9jKG1fc2NyaXB0Q29kZSwgbmV3U2l6ZSAq
IHNpemVvZihVQ2hhcikpKTsKICAgICBtX3NjcmlwdENvZGVDYXBhY2l0eSA9IG5ld1NpemU7CiB9
Cg==
</data>

          </attachment>
      

    </bug>

</bugzilla>