<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>325394</bug_id>
          
          <creation_ts>2026-09-26 20:38:20 -0700</creation_ts>
          <short_desc>[ATSPI] Unsandboxed web process crashes with RELEASE_ASSERT(!m_isConnecting) in AccessibilityAtspi::registerObject() when it cannot own its a11y bus name (e.g. Web Inspector in Flatpak)</short_desc>
          <delta_ts>2026-09-28 03:49:45 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Accessibility</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>PC</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <see_also>https://bugs.webkit.org/show_bug.cgi?id=325485</see_also>
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Fujii Hironori">fujii</reporter>
          <assigned_to name="Fujii Hironori">fujii</assigned_to>
          <cc>andresg_22</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>2255097</commentid>
    <comment_count>0</comment_count>
    <who name="Fujii Hironori">fujii</who>
    <bug_when>2026-09-26 20:38:20 -0700</bug_when>
    <thetext>(This report was written on my behalf by Claude Opus 5.5.)

A web process that is not running in a sandbox (e.g. the Web Inspector frontend process in a Flatpak app) crashes when an element loses focus because it is removed from the DOM:

  ASSERTION FAILED: !m_isConnecting
  Source/WebCore/accessibility/atspi/AccessibilityAtspi.cpp(375) : String WebCore::AccessibilityAtspi::registerObject(...)

It happens with a WPE WebKit based browser (wig) running in Flatpak. When I open Web Inspector and click around in it, the inspector process crashes almost immediately.

Backtrace (WebKit 321483@main):

  #3  WTFCrashWithInfo(int, char const*, char const*)
  #4  WebCore::AccessibilityAtspi::registerObject(...)
  #5  WebCore::AccessibilityObjectAtspi::registerObject()
  #6  WebCore::AccessibilityAtspi::stateChanged(WebCore::AccessibilityObjectAtspi&amp;, char const*, bool)
  #7  WebCore::AXObjectCache::platformHandleFocusedUIElementChanged(...)
  #8  WebCore::AXObjectCache::handleFocusedUIElementChanged(...)
  #9  WebCore::Document::setFocusedElement(...)
  #10 WebCore::Document::adjustFocusedNodeOnNodeRemoval(...)
  #11 WebCore::Document::nodeWillBeRemoved(WebCore::Node&amp;)
  #12 WebCore::ContainerNode::removeChild(WebCore::Node&amp;)
  #13 WebCore::Node::remove()
  #14 WebCore::jsElementPrototypeFunction_remove(...)
  ...
  #32 WebCore::JSEventListener::handleEvent(...)
  #38 WebCore::Element::dispatchMouseEvent(...)
  #40 WebCore::EventHandler::handleMousePressEvent(...)
  #42 WebKit::WebPage::mouseEvent(...)

Analysis:

1. The UI process always passes &quot;&lt;app-id&gt;.Sandboxed.WebProcess-&lt;UUID&gt;&quot; as the a11y bus name (WebProcessProxy::platformGetLaunchOptions() / WebProcessPool::generateNextAccessibilityBusName()), whether or not the web process is sandboxed.

2. Only a sandboxed web process spawned by flatpak-spawn gets permission to own that name (--sandbox-a11y-own-name). The Web Inspector process pool (defaultInspectorProcessPool()) doesn&apos;t enable the sandbox (m_sandboxEnabled defaults to false), so the inspector web process is spawned directly inside the app&apos;s sandbox. It connects to the a11y bus through the app&apos;s xdg-dbus-proxy, which doesn&apos;t allow owning that name. Normal web processes can end up in the same state if they are spawned without the sandbox.

3. AccessibilityAtspi::didConnect() calls g_bus_own_name_on_connection() with G_BUS_NAME_OWNER_FLAGS_DO_NOT_QUEUE and a null name_lost handler. If the name can&apos;t be acquired, didOwnName() is never called, so m_isConnecting stays true forever and m_registry stays null.

   I confirmed this state in a running inspector web process with gdb: m_isConnecting == true, m_connection != null, and the name isn&apos;t on the a11y bus.

4. Because m_registry is null, shouldEmitSignal() always returns true. So the first focus change reaches AccessibilityObjectAtspi::registerObject() -&gt; AccessibilityAtspi::registerObject(), and RELEASE_ASSERT(!m_isConnecting) fails.

Why it started happening recently:

The broken state in 3 has existed since the name ownership was added (284894@main, Oct 2024). It didn&apos;t cause crashes because accessibility was never enabled in the inspector process. Since 320566@main (&quot;AX: When multiple web views share a web process, only one reports correct accessibility bounds&quot;), the accessibility mode is global in the UI process and is broadcast to all web processes. So once accessibility is enabled for the inspected page&apos;s (sandboxed) web process, the inspector process gets an AXObjectCache too and hits the assertion.

With WebKit 320133@main (before 320566@main), gAccessibilityMode was MainThread in the page process and Off in the inspector process, and the inspector worked fine. With 321483@main (after it), the inspector process crashes after a few clicks. It also crashes the same way with 321997@main (2026-09-26).

Possible fixes:

- Pass a name_lost handler to g_bus_own_name_on_connection() and reset m_isConnecting (and handle the pending root registrations) when the name can&apos;t be owned. In that case either continue without owning a name, or disconnect.
- And/or don&apos;t try to own a &quot;Sandboxed&quot; name when the web process isn&apos;t sandboxed.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2255098</commentid>
    <comment_count>1</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2026-09-26 20:38:29 -0700</bug_when>
    <thetext>&lt;rdar://problem/188503396&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2255105</commentid>
    <comment_count>2</comment_count>
    <who name="Fujii Hironori">fujii</who>
    <bug_when>2026-09-26 21:44:21 -0700</bug_when>
    <thetext>Pull request: https://github.com/WebKit/WebKit/pull/75040</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2255106</commentid>
    <comment_count>3</comment_count>
    <who name="Fujii Hironori">fujii</who>
    <bug_when>2026-09-26 21:44:56 -0700</bug_when>
    <thetext>This can be reproduced without Flatpak, with a stock MiniBrowser (GTK, Release, current main), by using a private a11y bus whose policy doesn&apos;t allow owning the web process bus name.

The crash needs two web processes: one that owns its name and enables accessibility (which is then broadcast to all web processes since 320566@main), and one that can&apos;t own its name. A cross-site navigation gives us both, so Web Inspector isn&apos;t needed.

1. Two dbus-daemon configs. a11y-allow.conf:

&lt;!DOCTYPE busconfig PUBLIC &quot;-//freedesktop//DTD D-Bus Bus Configuration 1.0//EN&quot;
 &quot;http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd&quot;&gt;
&lt;busconfig&gt;
  &lt;type&gt;accessibility&lt;/type&gt;
  &lt;listen&gt;unix:tmpdir=/tmp&lt;/listen&gt;
  &lt;auth&gt;EXTERNAL&lt;/auth&gt;
  &lt;policy context=&quot;default&quot;&gt;
    &lt;allow send_destination=&quot;*&quot; eavesdrop=&quot;true&quot;/&gt;
    &lt;allow eavesdrop=&quot;true&quot;/&gt;
    &lt;allow own=&quot;*&quot;/&gt;
  &lt;/policy&gt;
&lt;/busconfig&gt;

   a11y-deny.conf is the same plus, inside &lt;policy&gt;:

    &lt;deny own_prefix=&quot;org.webkitgtk.MiniBrowser.Sandboxed&quot;/&gt;

2. Serve two files with &quot;python3 -m http.server 8765&quot;:

   a.html:
     &lt;!DOCTYPE html&gt;&lt;title&gt;A&lt;/title&gt;&lt;button&gt;hello&lt;/button&gt;
     &lt;script&gt;setTimeout(() =&gt; { location.href = &apos;http://localhost:8765/focus-remove.html&apos;; }, 8000);&lt;/script&gt;

   focus-remove.html:
     &lt;!DOCTYPE html&gt;
     &lt;input id=&quot;i&quot; autofocus&gt;
     &lt;script&gt;
     const i = document.getElementById(&apos;i&apos;);
     i.focus();
     setTimeout(() =&gt; { document.title = &apos;removing&apos;; i.remove(); document.title = &apos;removed&apos;; }, 3000);
     setTimeout(() =&gt; { document.title = &apos;alive&apos;; }, 5000);
     &lt;/script&gt;

3. Run (e.g. under xvfb-run):

   cp a11y-allow.conf a11y-live.conf
   dbus-daemon --config-file=a11y-live.conf --print-address --nofork &amp;   # use the printed address below
   export AT_SPI_BUS_ADDRESS=&lt;address&gt;
   /usr/libexec/at-spi2-registryd &amp;
   WEBKIT_DISABLE_SANDBOX_THIS_IS_DANGEROUS=1 Tools/Scripts/run-minibrowser --gtk --release http://127.0.0.1:8765/a.html &amp;
   # Walk the a11y tree with any AT on the same bus (accerciser, or a pyatspi script
   # that iterates Atspi.get_desktop(0)) so that the first web process enables accessibility.
   # Within 8 seconds (before a.html navigates away):
   cp a11y-deny.conf a11y-live.conf
   gdbus call -a &quot;$AT_SPI_BUS_ADDRESS&quot; -d org.freedesktop.DBus -o /org/freedesktop/DBus -m org.freedesktop.DBus.ReloadConfig

a.html then navigates to localhost, a new web process is spawned, it inherits the accessibility mode but can&apos;t own &quot;org.webkitgtk.MiniBrowser.Sandboxed.WebProcess-&lt;UUID&gt;&quot;, and it crashes at load completion:

  WTFCrashWithInfo
  WebCore::AccessibilityAtspi::registerObject(...)
  WebCore::AccessibilityObjectAtspi::registerObject()
  WebCore::AccessibilityAtspi::stateChanged(...)
  WebCore::AXObjectCache::frameLoadingEventPlatformNotification(...)
  WebCore::AXObjectCache::frameLoadingEventNotification(...)
  WebCore::FrameLoader::checkLoadCompleteForThisFrame(...)

It&apos;s the same RELEASE_ASSERT(!m_isConnecting) as in the Flatpak inspector case, reached from a different caller. It crashed on every run.

With the fix in https://github.com/WebKit/WebKit/pull/75040, the web process instead logs &quot;Can&apos;t own name ... on a11y bus&quot;, and focus-remove.html runs to the end without crashing (3 runs).

— Written by Claude Opus 5.5</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2255336</commentid>
    <comment_count>4</comment_count>
    <who name="EWS">ews-feeder</who>
    <bug_when>2026-09-27 21:35:08 -0700</bug_when>
    <thetext>Committed 322028@main (08a38d85de0f): &lt;https://commits.webkit.org/322028@main&gt;

Reviewed commits have been landed. Closing PR #75040 and removing active labels.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>