<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>63216</bug_id>
          
          <creation_ts>2011-06-22 18:45:05 -0700</creation_ts>
          <short_desc>[Chromium] Invalid write inside WebKit::FrameLoaderClientImpl::dispatchDidClearWindowObjectInWorld</short_desc>
          <delta_ts>2011-06-27 00:33:38 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Platform</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Hajime Morrita">morrita</reporter>
          <assigned_to name="Hajime Morrita">morrita</assigned_to>
          <cc>tkent</cc>
    
    <cc>tony</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>425857</commentid>
    <comment_count>0</comment_count>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2011-06-22 18:45:05 -0700</bug_when>
    <thetext>From http://code.google.com/p/chromium/issues/detail?id=84774.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>426024</commentid>
    <comment_count>1</comment_count>
      <attachid>98324</attachid>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2011-06-23 01:53:36 -0700</bug_when>
    <thetext>Created attachment 98324
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>426029</commentid>
    <comment_count>2</comment_count>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2011-06-23 01:56:30 -0700</bug_when>
    <thetext>This looks same. http://code.google.com/p/chromium/issues/detail?id=86808

I suspect this change might cause another ASAN error, but this looks obvious leak.
So I&apos;d like to see what happens with this change.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>426040</commentid>
    <comment_count>3</comment_count>
      <attachid>98324</attachid>
    <who name="Kent Tamura">tkent</who>
    <bug_when>2011-06-23 02:12:52 -0700</bug_when>
    <thetext>Comment on attachment 98324
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=98324&amp;action=review

&gt; Tools/DumpRenderTree/chromium/TestShell.cpp:153
&gt; +    delete m_webViewHost;

Raw new&amp;delete are not good.
We had better make m_webViewHost OwnPtr&lt;WebViewHost&gt;, and TestShell::createNewWindow() should return PassOwnPtr&lt;WebViewHost&gt;.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>426043</commentid>
    <comment_count>4</comment_count>
      <attachid>98324</attachid>
    <who name="Kent Tamura">tkent</who>
    <bug_when>2011-06-23 02:19:02 -0700</bug_when>
    <thetext>Comment on attachment 98324
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=98324&amp;action=review

&gt;&gt; Tools/DumpRenderTree/chromium/TestShell.cpp:153
&gt;&gt; +    delete m_webViewHost;
&gt; 
&gt; Raw new&amp;delete are not good.
&gt; We had better make m_webViewHost OwnPtr&lt;WebViewHost&gt;, and TestShell::createNewWindow() should return PassOwnPtr&lt;WebViewHost&gt;.

Changing createNewWindow() might be complex.  So, just making m_webViewHost OwnPtr&lt;WebViewHost&gt; is enough.
Note that we can&apos;t do closeWindow(m_webViewHost).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>426770</commentid>
    <comment_count>5</comment_count>
      <attachid>98467</attachid>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2011-06-24 00:32:11 -0700</bug_when>
    <thetext>Created attachment 98467
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>426771</commentid>
    <comment_count>6</comment_count>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2011-06-24 00:34:47 -0700</bug_when>
    <thetext>Kent-san, thank you for taking a look!

&gt; Changing createNewWindow() might be complex.  So, just making m_webViewHost OwnPtr&lt;WebViewHost&gt; is enough.
&gt; Note that we can&apos;t do closeWindow(m_webViewHost).
Sure. I did it on the updated patch.

&gt; Changing createNewWindow() might be complex.  So, just making m_webViewHost OwnPtr&lt;WebViewHost&gt; is enough.
&gt; Note that we can&apos;t do closeWindow(m_webViewHost).
Ah, I didn&apos;t notice that...
Fortunately, there is no such call at this time.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>426804</commentid>
    <comment_count>7</comment_count>
      <attachid>98467</attachid>
    <who name="Kent Tamura">tkent</who>
    <bug_when>2011-06-24 03:35:11 -0700</bug_when>
    <thetext>Comment on attachment 98467
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=98467&amp;action=review

&gt; Tools/DumpRenderTree/chromium/TestShell.cpp:153
&gt; +    m_webViewHost.clear();

No need to call clear() explicitly. ~OwnPtr() is called automatically.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>427170</commentid>
    <comment_count>8</comment_count>
    <who name="Tony Chang">tony</who>
    <bug_when>2011-06-24 14:56:22 -0700</bug_when>
    <thetext>Committed http://trac.webkit.org/changeset/89663 .</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>427729</commentid>
    <comment_count>9</comment_count>
    <who name="Hajime Morrita">morrita</who>
    <bug_when>2011-06-27 00:33:38 -0700</bug_when>
    <thetext>Thanks you for updating this, Tony.
It looks I forgot to do it.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>98324</attachid>
            <date>2011-06-23 01:53:36 -0700</date>
            <delta_ts>2011-06-24 00:32:06 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-63216-20110623175334.patch</filename>
            <type>text/plain</type>
            <size>1253</size>
            <attacher name="Hajime Morrita">morrita</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogODk1NDMKZGlmZiAtLWdpdCBhL1Rvb2xzL0NoYW5nZUxvZyBi
L1Rvb2xzL0NoYW5nZUxvZwppbmRleCBjZTIyYjdjNWE1ZTFjY2NiMTVkZjQ0OTg2OTE4NmUwNGIw
NzE1ZWFlLi4zMDhjZTBmNDBiOGMyYzEzNTI4ODdiNmI2MWIwMzFkMmIyNDNlMmMwIDEwMDY0NAot
LS0gYS9Ub29scy9DaGFuZ2VMb2cKKysrIGIvVG9vbHMvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTUg
QEAKKzIwMTEtMDYtMjMgIE1PUklUQSBIYWppbWUgIDxtb3JyaXRhQGdvb2dsZS5jb20+CisKKyAg
ICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAgICAgW0Nocm9taXVtXSBJ
bnZhbGlkIHdyaXRlIGluc2lkZSBXZWJLaXQ6OkZyYW1lTG9hZGVyQ2xpZW50SW1wbDo6ZGlzcGF0
Y2hEaWRDbGVhcldpbmRvd09iamVjdEluV29ybGQKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtp
dC5vcmcvc2hvd19idWcuY2dpP2lkPTYzMjE2CisKKyAgICAgICAgRGVsZXRlZCBtX3dlYlZpZXdI
b3N0IHdoaWNoIGxvb2tzIGxlYWtlZC4KKyAgICAgICAgCisgICAgICAgICogRHVtcFJlbmRlclRy
ZWUvY2hyb21pdW0vVGVzdFNoZWxsLmNwcDoKKyAgICAgICAgKFRlc3RTaGVsbDo6flRlc3RTaGVs
bCk6CisKIDIwMTEtMDYtMjMgIERpcmsgUHJhbmtlICA8ZHByYW5rZUBjaHJvbWl1bS5vcmc+CiAK
ICAgICAgICAgUmV2aWV3ZWQgYnkgRXJpYyBTZWlkZWwuCmRpZmYgLS1naXQgYS9Ub29scy9EdW1w
UmVuZGVyVHJlZS9jaHJvbWl1bS9UZXN0U2hlbGwuY3BwIGIvVG9vbHMvRHVtcFJlbmRlclRyZWUv
Y2hyb21pdW0vVGVzdFNoZWxsLmNwcAppbmRleCAwYTM2NjcxZDYyY2UwNjRjNzAwMWU5MTVmNGE3
MmQ2MmY5ZDVkZDc0Li5mYjExNDIyNWI1OTU1MjIzNzIxMGU4MGY0YjhjNWY4ZDA5YTkxNzAzIDEw
MDY0NAotLS0gYS9Ub29scy9EdW1wUmVuZGVyVHJlZS9jaHJvbWl1bS9UZXN0U2hlbGwuY3BwCisr
KyBiL1Rvb2xzL0R1bXBSZW5kZXJUcmVlL2Nocm9taXVtL1Rlc3RTaGVsbC5jcHAKQEAgLTE1MCw2
ICsxNTAsNyBAQCBUZXN0U2hlbGw6On5UZXN0U2hlbGwoKQogCiAgICAgLy8gRGVzdHJveSB0aGUg
V2ViVmlldyBiZWZvcmUgaXRzIFdlYlZpZXdIb3N0LgogICAgIG1fZHJ0RGV2VG9vbHNBZ2VudC0+
c2V0V2ViVmlldygwKTsKKyAgICBkZWxldGUgbV93ZWJWaWV3SG9zdDsKIH0KIAogdm9pZCBUZXN0
U2hlbGw6OmNyZWF0ZURSVERldlRvb2xzQ2xpZW50KERSVERldlRvb2xzQWdlbnQqIGFnZW50KQo=
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>98467</attachid>
            <date>2011-06-24 00:32:11 -0700</date>
            <delta_ts>2011-06-24 03:35:11 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-63216-20110624163210.patch</filename>
            <type>text/plain</type>
            <size>2950</size>
            <attacher name="Hajime Morrita">morrita</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogODk1NDMKZGlmZiAtLWdpdCBhL1Rvb2xzL0NoYW5nZUxvZyBi
L1Rvb2xzL0NoYW5nZUxvZwppbmRleCBjZTIyYjdjNWE1ZTFjY2NiMTVkZjQ0OTg2OTE4NmUwNGIw
NzE1ZWFlLi4xMDc4NjIwYmQ2MjI4NWMzOTMxMGVkNDgyMjcxNDE5OTQ2OWM0OTliIDEwMDY0NAot
LS0gYS9Ub29scy9DaGFuZ2VMb2cKKysrIGIvVG9vbHMvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTYg
QEAKKzIwMTEtMDYtMjMgIE1PUklUQSBIYWppbWUgIDxtb3JyaXRhQGdvb2dsZS5jb20+CisKKyAg
ICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAgICAgW0Nocm9taXVtXSBJ
bnZhbGlkIHdyaXRlIGluc2lkZSBXZWJLaXQ6OkZyYW1lTG9hZGVyQ2xpZW50SW1wbDo6ZGlzcGF0
Y2hEaWRDbGVhcldpbmRvd09iamVjdEluV29ybGQKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtp
dC5vcmcvc2hvd19idWcuY2dpP2lkPTYzMjE2CisKKyAgICAgICAgRGVsZXRlZCBtX3dlYlZpZXdI
b3N0IHdoaWNoIGxvb2tzIGxlYWtlZC4KKyAgICAgICAgCisgICAgICAgICogRHVtcFJlbmRlclRy
ZWUvY2hyb21pdW0vVGVzdFNoZWxsLmg6CisgICAgICAgICogRHVtcFJlbmRlclRyZWUvY2hyb21p
dW0vVGVzdFNoZWxsLmNwcDoKKyAgICAgICAgKFRlc3RTaGVsbDo6flRlc3RTaGVsbCk6CisKIDIw
MTEtMDYtMjMgIERpcmsgUHJhbmtlICA8ZHByYW5rZUBjaHJvbWl1bS5vcmc+CiAKICAgICAgICAg
UmV2aWV3ZWQgYnkgRXJpYyBTZWlkZWwuCmRpZmYgLS1naXQgYS9Ub29scy9EdW1wUmVuZGVyVHJl
ZS9jaHJvbWl1bS9UZXN0U2hlbGwuY3BwIGIvVG9vbHMvRHVtcFJlbmRlclRyZWUvY2hyb21pdW0v
VGVzdFNoZWxsLmNwcAppbmRleCAwYTM2NjcxZDYyY2UwNjRjNzAwMWU5MTVmNGE3MmQ2MmY5ZDVk
ZDc0Li4xNjcxYTMzMTljMjk1Yjk4NmQ3YmFmNDQwZGFjMDJhODE4MDY1NTRkIDEwMDY0NAotLS0g
YS9Ub29scy9EdW1wUmVuZGVyVHJlZS9jaHJvbWl1bS9UZXN0U2hlbGwuY3BwCisrKyBiL1Rvb2xz
L0R1bXBSZW5kZXJUcmVlL2Nocm9taXVtL1Rlc3RTaGVsbC5jcHAKQEAgLTEzOCw3ICsxMzgsNyBA
QCBUZXN0U2hlbGw6OlRlc3RTaGVsbChib29sIHRlc3RTaGVsbE1vZGUpCiB2b2lkIFRlc3RTaGVs
bDo6Y3JlYXRlTWFpbldpbmRvdygpCiB7CiAgICAgbV9kcnREZXZUb29sc0FnZW50ID0gYWRvcHRQ
dHIobmV3IERSVERldlRvb2xzQWdlbnQpOwotICAgIG1fd2ViVmlld0hvc3QgPSBjcmVhdGVOZXdX
aW5kb3coV2ViVVJMKCksIG1fZHJ0RGV2VG9vbHNBZ2VudC5nZXQoKSk7CisgICAgbV93ZWJWaWV3
SG9zdCA9IGFkb3B0UHRyKGNyZWF0ZU5ld1dpbmRvdyhXZWJVUkwoKSwgbV9kcnREZXZUb29sc0Fn
ZW50LmdldCgpKSk7CiAgICAgbV93ZWJWaWV3ID0gbV93ZWJWaWV3SG9zdC0+d2ViVmlldygpOwog
ICAgIG1fZHJ0RGV2VG9vbHNBZ2VudC0+c2V0V2ViVmlldyhtX3dlYlZpZXcpOwogfQpAQCAtMTUw
LDYgKzE1MCw3IEBAIFRlc3RTaGVsbDo6flRlc3RTaGVsbCgpCiAKICAgICAvLyBEZXN0cm95IHRo
ZSBXZWJWaWV3IGJlZm9yZSBpdHMgV2ViVmlld0hvc3QuCiAgICAgbV9kcnREZXZUb29sc0FnZW50
LT5zZXRXZWJWaWV3KDApOworICAgIG1fd2ViVmlld0hvc3QuY2xlYXIoKTsKIH0KIAogdm9pZCBU
ZXN0U2hlbGw6OmNyZWF0ZURSVERldlRvb2xzQ2xpZW50KERSVERldlRvb2xzQWdlbnQqIGFnZW50
KQpkaWZmIC0tZ2l0IGEvVG9vbHMvRHVtcFJlbmRlclRyZWUvY2hyb21pdW0vVGVzdFNoZWxsLmgg
Yi9Ub29scy9EdW1wUmVuZGVyVHJlZS9jaHJvbWl1bS9UZXN0U2hlbGwuaAppbmRleCAzMzc2NTdm
NDU5YjcyOTJmZTFmNWFhMmRjY2YzMjEyZmY0YTlmMzRmLi45YTFmYzE5MzcyMjYyYjg0MmMxZDRl
NWQ5MmM3N2EzZDc5YzgzMzcwIDEwMDY0NAotLS0gYS9Ub29scy9EdW1wUmVuZGVyVHJlZS9jaHJv
bWl1bS9UZXN0U2hlbGwuaAorKysgYi9Ub29scy9EdW1wUmVuZGVyVHJlZS9jaHJvbWl1bS9UZXN0
U2hlbGwuaApAQCAtODcsNyArODcsNyBAQCBwdWJsaWM6CiAgICAgLy8gVGhlIG1haW4gV2ViVmll
dy4KICAgICBXZWJLaXQ6OldlYlZpZXcqIHdlYlZpZXcoKSBjb25zdCB7IHJldHVybiBtX3dlYlZp
ZXc7IH0KICAgICAvLyBSZXR1cm5zIHRoZSBob3N0IGZvciB0aGUgbWFpbiBXZWJWaWV3LgotICAg
IFdlYlZpZXdIb3N0KiB3ZWJWaWV3SG9zdCgpIGNvbnN0IHsgcmV0dXJuIG1fd2ViVmlld0hvc3Q7
IH0KKyAgICBXZWJWaWV3SG9zdCogd2ViVmlld0hvc3QoKSBjb25zdCB7IHJldHVybiBtX3dlYlZp
ZXdIb3N0LmdldCgpOyB9CiAgICAgTGF5b3V0VGVzdENvbnRyb2xsZXIqIGxheW91dFRlc3RDb250
cm9sbGVyKCkgY29uc3QgeyByZXR1cm4gbV9sYXlvdXRUZXN0Q29udHJvbGxlci5nZXQoKTsgfQog
ICAgIEV2ZW50U2VuZGVyKiBldmVudFNlbmRlcigpIGNvbnN0IHsgcmV0dXJuIG1fZXZlbnRTZW5k
ZXIuZ2V0KCk7IH0KICAgICBBY2Nlc3NpYmlsaXR5Q29udHJvbGxlciogYWNjZXNzaWJpbGl0eUNv
bnRyb2xsZXIoKSBjb25zdCB7IHJldHVybiBtX2FjY2Vzc2liaWxpdHlDb250cm9sbGVyLmdldCgp
OyB9CkBAIC0xOTIsOCArMTkyLDggQEAgcHJpdmF0ZToKICAgICBXZWJLaXQ6OldlYlZpZXcqIG1f
d2ViVmlldzsKICAgICBXZWJLaXQ6OldlYldpZGdldCogbV9mb2N1c2VkV2lkZ2V0OwogICAgIGJv
b2wgbV90ZXN0U2hlbGxNb2RlOwotICAgIFdlYlZpZXdIb3N0KiBtX3dlYlZpZXdIb3N0OwogICAg
IFdlYlZpZXdIb3N0KiBtX2RldlRvb2xzOworICAgIE93blB0cjxXZWJWaWV3SG9zdD4gbV93ZWJW
aWV3SG9zdDsKICAgICBPd25QdHI8V2ViUGVybWlzc2lvbnM+IG1fd2ViUGVybWlzc2lvbnM7CiAg
ICAgT3duUHRyPERSVERldlRvb2xzQWdlbnQ+IG1fZHJ0RGV2VG9vbHNBZ2VudDsKICAgICBPd25Q
dHI8RFJURGV2VG9vbHNDbGllbnQ+IG1fZHJ0RGV2VG9vbHNDbGllbnQ7Cg==
</data>
<flag name="review"
          id="92697"
          type_id="1"
          status="+"
          setter="tkent"
    />
          </attachment>
      

    </bug>

</bugzilla>