<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>66002</bug_id>
          
          <creation_ts>2011-08-10 12:09:30 -0700</creation_ts>
          <short_desc>Web Inspector: do not evaluate watch expressions on load.</short_desc>
          <delta_ts>2011-08-11 00:56:34 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Web Inspector (Deprecated)</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>0</everconfirmed>
          <reporter name="Pavel Feldman">pfeldman</reporter>
          <assigned_to name="Pavel Feldman">pfeldman</assigned_to>
          <cc>apavlov</cc>
    
    <cc>bweinstein</cc>
    
    <cc>joepeck</cc>
    
    <cc>keishi</cc>
    
    <cc>loislo</cc>
    
    <cc>pfeldman</cc>
    
    <cc>pmuellr</cc>
    
    <cc>rik</cc>
    
    <cc>timothy</cc>
    
    <cc>webkit.review.bot</cc>
    
    <cc>yurys</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>449285</commentid>
    <comment_count>0</comment_count>
    <who name="Pavel Feldman">pfeldman</who>
    <bug_when>2011-08-10 12:09:30 -0700</bug_when>
    <thetext>Only do that upon scripts panel &quot;show&quot;, stepping and reloads.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>449301</commentid>
    <comment_count>1</comment_count>
      <attachid>103516</attachid>
    <who name="Pavel Feldman">pfeldman</who>
    <bug_when>2011-08-10 12:27:21 -0700</bug_when>
    <thetext>Created attachment 103516
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>449611</commentid>
    <comment_count>2</comment_count>
      <attachid>103516</attachid>
    <who name="Yury Semikhatsky">yurys</who>
    <bug_when>2011-08-10 23:20:54 -0700</bug_when>
    <thetext>Comment on attachment 103516
Patch

Is there a chance we have it tested?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>449612</commentid>
    <comment_count>3</comment_count>
      <attachid>103516</attachid>
    <who name="Pavel Feldman">pfeldman</who>
    <bug_when>2011-08-10 23:25:36 -0700</bug_when>
    <thetext>Comment on attachment 103516
Patch

By the time we get control on the front-end, malicious watch update is already performed, not sure how to test this very case :(</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>449620</commentid>
    <comment_count>4</comment_count>
    <who name="Yury Semikhatsky">yurys</who>
    <bug_when>2011-08-10 23:44:16 -0700</bug_when>
    <thetext>(In reply to comment #3)
&gt; (From update of attachment 103516 [details])
&gt; By the time we get control on the front-end, malicious watch update is already performed, not sure how to test this very case :(

Well, the watch expression can have a side effect on the inspected page, say increment a counter in it and we can check that after frontend opening it has not been incremented yet. We would need to issue a request on the very early stage of the frontend loading though.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>449648</commentid>
    <comment_count>5</comment_count>
      <attachid>103516</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-08-11 00:56:29 -0700</bug_when>
    <thetext>Comment on attachment 103516
Patch

Clearing flags on attachment: 103516

Committed r92827: &lt;http://trac.webkit.org/changeset/92827&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>449649</commentid>
    <comment_count>6</comment_count>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-08-11 00:56:34 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>103516</attachid>
            <date>2011-08-10 12:27:21 -0700</date>
            <delta_ts>2011-08-11 00:56:29 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-66002-20110810232719.patch</filename>
            <type>text/plain</type>
            <size>5899</size>
            <attacher name="Pavel Feldman">pfeldman</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogOTI3NjkKZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJDb3JlL0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJDb3JlL0NoYW5nZUxvZwppbmRleCAyNzhkOTEyMmYxYTUwMDlh
OWVkMTJkNWQ3MGYzMzBmOTA3ZWU0NWMwLi5kZDM4MjkxZTg0ZmI3ZThlNTg2OThmYTMwOWYwZTg5
ZmI4MjM3YWI2IDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKKysrIGIvU291
cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMjIgQEAKKzIwMTEtMDgtMTAgIFBhdmVs
IEZlbGRtYW4gIDxwZmVsZG1hbkBnb29nbGUuY29tPgorCisgICAgICAgIFdlYiBJbnNwZWN0b3I6
IGRvIG5vdCBldmFsdWF0ZSB3YXRjaCBleHByZXNzaW9ucyBvbiBsb2FkLgorICAgICAgICBodHRw
czovL2J1Z3Mud2Via2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9NjYwMDIKKworICAgICAgICBSZXZp
ZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICAqIGluc3BlY3Rvci9mcm9udC1lbmQv
U2NyaXB0c1BhbmVsLmpzOgorICAgICAgICAoV2ViSW5zcGVjdG9yLlNjcmlwdHNQYW5lbC5wcm90
b3R5cGUuc2hvdyk6CisgICAgICAgIChXZWJJbnNwZWN0b3IuU2NyaXB0c1BhbmVsLnByb3RvdHlw
ZS5oaWRlKToKKyAgICAgICAgKFdlYkluc3BlY3Rvci5TY3JpcHRzUGFuZWwucHJvdG90eXBlLnJl
c2V0KToKKyAgICAgICAgKiBpbnNwZWN0b3IvZnJvbnQtZW5kL1dhdGNoRXhwcmVzc2lvbnNTaWRl
YmFyUGFuZS5qczoKKyAgICAgICAgKFdlYkluc3BlY3Rvci5XYXRjaEV4cHJlc3Npb25zU2lkZWJh
clBhbmUpOgorICAgICAgICAoV2ViSW5zcGVjdG9yLldhdGNoRXhwcmVzc2lvbnNTaWRlYmFyUGFu
ZS5wcm90b3R5cGUuaGlkZSk6CisgICAgICAgIChXZWJJbnNwZWN0b3IuV2F0Y2hFeHByZXNzaW9u
c1NpZGViYXJQYW5lLnByb3RvdHlwZS5yZXNldCk6CisgICAgICAgIChXZWJJbnNwZWN0b3IuV2F0
Y2hFeHByZXNzaW9uc1NpZGViYXJQYW5lLnByb3RvdHlwZS5yZWZyZXNoRXhwcmVzc2lvbnMpOgor
ICAgICAgICAoV2ViSW5zcGVjdG9yLldhdGNoRXhwcmVzc2lvbnNTaWRlYmFyUGFuZS5wcm90b3R5
cGUuX3JlZnJlc2hFeHByZXNzaW9uc0lmTmVlZGVkKToKKyAgICAgICAgKFdlYkluc3BlY3Rvci5X
YXRjaEV4cHJlc3Npb25zU2lkZWJhclBhbmUucHJvdG90eXBlLl9yZWZyZXNoQnV0dG9uQ2xpY2tl
ZCk6CisKIDIwMTEtMDgtMTAgIEJlbmphbWluIFBvdWxhaW4gIDxiZW5qYW1pbkB3ZWJraXQub3Jn
PgogCiAgICAgICAgIFVuaWZ5IHRoZSB3YXkgd2UgZ2VuZXJhdGUgSFRNTCBmb3IgYW4gaW1hZ2Ug
aW4gdGhlIENsaXBib2FyZApkaWZmIC0tZ2l0IGEvU291cmNlL1dlYkNvcmUvaW5zcGVjdG9yL2Zy
b250LWVuZC9TY3JpcHRzUGFuZWwuanMgYi9Tb3VyY2UvV2ViQ29yZS9pbnNwZWN0b3IvZnJvbnQt
ZW5kL1NjcmlwdHNQYW5lbC5qcwppbmRleCA5MmVjM2JiYTNiYmYwNzljNWVjNTQ5ZTFmMWQ2M2Yw
YTRkOTA2NDFkLi5iZTBhZWJkMTRlM2ViZjIwNDQ4NTVjMjlhYjVjMzVkMDFhOWM3ZGVjIDEwMDY0
NAotLS0gYS9Tb3VyY2UvV2ViQ29yZS9pbnNwZWN0b3IvZnJvbnQtZW5kL1NjcmlwdHNQYW5lbC5q
cworKysgYi9Tb3VyY2UvV2ViQ29yZS9pbnNwZWN0b3IvZnJvbnQtZW5kL1NjcmlwdHNQYW5lbC5q
cwpAQCAtMjE0LDYgKzIxNCw3IEBAIFdlYkluc3BlY3Rvci5TY3JpcHRzUGFuZWwucHJvdG90eXBl
ID0gewogCiAgICAgICAgIGlmICh0aGlzLnZpc2libGVWaWV3KQogICAgICAgICAgICAgdGhpcy52
aXNpYmxlVmlldy5zaG93KHRoaXMudmlld3NDb250YWluZXJFbGVtZW50KTsKKyAgICAgICAgdGhp
cy5zaWRlYmFyUGFuZXMud2F0Y2hFeHByZXNzaW9ucy5zaG93KCk7CiAgICAgfSwKIAogICAgIGhp
ZGU6IGZ1bmN0aW9uKCkKQEAgLTIyMSw2ICsyMjIsNyBAQCBXZWJJbnNwZWN0b3IuU2NyaXB0c1Bh
bmVsLnByb3RvdHlwZSA9IHsKICAgICAgICAgaWYgKHRoaXMudmlzaWJsZVZpZXcpCiAgICAgICAg
ICAgICB0aGlzLnZpc2libGVWaWV3LmhpZGUoKTsKICAgICAgICAgV2ViSW5zcGVjdG9yLlBhbmVs
LnByb3RvdHlwZS5oaWRlLmNhbGwodGhpcyk7CisgICAgICAgIHRoaXMuc2lkZWJhclBhbmVzLndh
dGNoRXhwcmVzc2lvbnMuaGlkZSgpOwogICAgIH0sCiAKICAgICBnZXQgYnJlYWtwb2ludHNBY3Rp
dmF0ZWQoKQpAQCAtNTQwLDcgKzU0Miw3IEBAIFdlYkluc3BlY3Rvci5TY3JpcHRzUGFuZWwucHJv
dG90eXBlID0gewogICAgICAgICB0aGlzLnZpZXdzQ29udGFpbmVyRWxlbWVudC5yZW1vdmVDaGls
ZHJlbigpOwogCiAgICAgICAgIHRoaXMuc2lkZWJhclBhbmVzLmpzQnJlYWtwb2ludHMucmVzZXQo
KTsKLSAgICAgICAgdGhpcy5zaWRlYmFyUGFuZXMud2F0Y2hFeHByZXNzaW9ucy5yZWZyZXNoRXhw
cmVzc2lvbnMoKTsKKyAgICAgICAgdGhpcy5zaWRlYmFyUGFuZXMud2F0Y2hFeHByZXNzaW9ucy5y
ZXNldCgpOwogICAgICAgICBpZiAoIXByZXNlcnZlSXRlbXMgJiYgdGhpcy5zaWRlYmFyUGFuZXMu
d29ya2VycykKICAgICAgICAgICAgIHRoaXMuc2lkZWJhclBhbmVzLndvcmtlcnMucmVzZXQoKTsK
ICAgICB9LApkaWZmIC0tZ2l0IGEvU291cmNlL1dlYkNvcmUvaW5zcGVjdG9yL2Zyb250LWVuZC9X
YXRjaEV4cHJlc3Npb25zU2lkZWJhclBhbmUuanMgYi9Tb3VyY2UvV2ViQ29yZS9pbnNwZWN0b3Iv
ZnJvbnQtZW5kL1dhdGNoRXhwcmVzc2lvbnNTaWRlYmFyUGFuZS5qcwppbmRleCBhM2M2NzQ5ZmQy
OGFkN2Q0ZjZjNWYwZDM0MmNlZTg5MDllMTYyOWZkLi5mZDJjNTY1ZDcwNWMwMDYyNDRmODJjNjQy
YmFiZDk0YThlMTNiYzM3IDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViQ29yZS9pbnNwZWN0b3IvZnJv
bnQtZW5kL1dhdGNoRXhwcmVzc2lvbnNTaWRlYmFyUGFuZS5qcworKysgYi9Tb3VyY2UvV2ViQ29y
ZS9pbnNwZWN0b3IvZnJvbnQtZW5kL1dhdGNoRXhwcmVzc2lvbnNTaWRlYmFyUGFuZS5qcwpAQCAt
MzEsMjkgKzMxLDU4IEBACiBXZWJJbnNwZWN0b3IuV2F0Y2hFeHByZXNzaW9uc1NpZGViYXJQYW5l
ID0gZnVuY3Rpb24oKQogewogICAgIFdlYkluc3BlY3Rvci5TaWRlYmFyUGFuZS5jYWxsKHRoaXMs
IFdlYkluc3BlY3Rvci5VSVN0cmluZygiV2F0Y2ggRXhwcmVzc2lvbnMiKSk7Ci0gICAgdGhpcy5y
ZXNldCgpOworCisgICAgdGhpcy5zZWN0aW9uID0gbmV3IFdlYkluc3BlY3Rvci5XYXRjaEV4cHJl
c3Npb25zU2VjdGlvbigpOworICAgIHRoaXMuYm9keUVsZW1lbnQuYXBwZW5kQ2hpbGQodGhpcy5z
ZWN0aW9uLmVsZW1lbnQpOworCisgICAgdmFyIHJlZnJlc2hCdXR0b24gPSBkb2N1bWVudC5jcmVh
dGVFbGVtZW50KCJidXR0b24iKTsKKyAgICByZWZyZXNoQnV0dG9uLmNsYXNzTmFtZSA9ICJwYW5l
LXRpdGxlLWJ1dHRvbiByZWZyZXNoIjsKKyAgICByZWZyZXNoQnV0dG9uLmFkZEV2ZW50TGlzdGVu
ZXIoImNsaWNrIiwgdGhpcy5fcmVmcmVzaEJ1dHRvbkNsaWNrZWQuYmluZCh0aGlzKSwgZmFsc2Up
OworICAgIHRoaXMudGl0bGVFbGVtZW50LmFwcGVuZENoaWxkKHJlZnJlc2hCdXR0b24pOworCisg
ICAgdmFyIGFkZEJ1dHRvbiA9IGRvY3VtZW50LmNyZWF0ZUVsZW1lbnQoImJ1dHRvbiIpOworICAg
IGFkZEJ1dHRvbi5jbGFzc05hbWUgPSAicGFuZS10aXRsZS1idXR0b24gYWRkIjsKKyAgICBhZGRC
dXR0b24uYWRkRXZlbnRMaXN0ZW5lcigiY2xpY2siLCB0aGlzLl9hZGRCdXR0b25DbGlja2VkLmJp
bmQodGhpcyksIGZhbHNlKTsKKyAgICB0aGlzLnRpdGxlRWxlbWVudC5hcHBlbmRDaGlsZChhZGRC
dXR0b24pOworICAgIHRoaXMuX3JlcXVpcmVzVXBkYXRlID0gdHJ1ZTsKIH0KIAogV2ViSW5zcGVj
dG9yLldhdGNoRXhwcmVzc2lvbnNTaWRlYmFyUGFuZS5wcm90b3R5cGUgPSB7Ci0gICAgcmVzZXQ6
IGZ1bmN0aW9uKCkKKyAgICBzaG93OiBmdW5jdGlvbigpCiAgICAgewotICAgICAgICB0aGlzLmJv
ZHlFbGVtZW50LnJlbW92ZUNoaWxkcmVuKCk7CisgICAgICAgIHRoaXMuX3Zpc2libGUgPSB0cnVl
OwogCi0gICAgICAgIHRoaXMuZXhwYW5kZWQgPSBXZWJJbnNwZWN0b3Iuc2V0dGluZ3Mud2F0Y2hF
eHByZXNzaW9ucy5nZXQoKS5sZW5ndGggPiAwOwotICAgICAgICB0aGlzLnNlY3Rpb24gPSBuZXcg
V2ViSW5zcGVjdG9yLldhdGNoRXhwcmVzc2lvbnNTZWN0aW9uKCk7Ci0gICAgICAgIHRoaXMuYm9k
eUVsZW1lbnQuYXBwZW5kQ2hpbGQodGhpcy5zZWN0aW9uLmVsZW1lbnQpOworICAgICAgICAvLyBF
eHBhbmQgYW5kIHVwZGF0ZSB3YXRjaGVzIGZpcnN0IHRpbWUgdGhleSBhcmUgc2hvd24uCisgICAg
ICAgIGlmICghdGhpcy5fd2FzU2hvd24gJiYgV2ViSW5zcGVjdG9yLnNldHRpbmdzLndhdGNoRXhw
cmVzc2lvbnMuZ2V0KCkubGVuZ3RoID4gMCkKKyAgICAgICAgICAgIHRoaXMuZXhwYW5kZWQgPSB0
cnVlOwogCi0gICAgICAgIHZhciByZWZyZXNoQnV0dG9uID0gZG9jdW1lbnQuY3JlYXRlRWxlbWVu
dCgiYnV0dG9uIik7Ci0gICAgICAgIHJlZnJlc2hCdXR0b24uY2xhc3NOYW1lID0gInBhbmUtdGl0
bGUtYnV0dG9uIHJlZnJlc2giOwotICAgICAgICByZWZyZXNoQnV0dG9uLmFkZEV2ZW50TGlzdGVu
ZXIoImNsaWNrIiwgdGhpcy5fcmVmcmVzaEJ1dHRvbkNsaWNrZWQuYmluZCh0aGlzKSwgZmFsc2Up
OwotICAgICAgICB0aGlzLnRpdGxlRWxlbWVudC5hcHBlbmRDaGlsZChyZWZyZXNoQnV0dG9uKTsK
KyAgICAgICAgdGhpcy5fcmVmcmVzaEV4cHJlc3Npb25zSWZOZWVkZWQoKTsKKyAgICAgICAgdGhp
cy5fd2FzU2hvd24gPSB0cnVlOworICAgIH0sCiAKLSAgICAgICAgdmFyIGFkZEJ1dHRvbiA9IGRv
Y3VtZW50LmNyZWF0ZUVsZW1lbnQoImJ1dHRvbiIpOwotICAgICAgICBhZGRCdXR0b24uY2xhc3NO
YW1lID0gInBhbmUtdGl0bGUtYnV0dG9uIGFkZCI7Ci0gICAgICAgIGFkZEJ1dHRvbi5hZGRFdmVu
dExpc3RlbmVyKCJjbGljayIsIHRoaXMuX2FkZEJ1dHRvbkNsaWNrZWQuYmluZCh0aGlzKSwgZmFs
c2UpOwotICAgICAgICB0aGlzLnRpdGxlRWxlbWVudC5hcHBlbmRDaGlsZChhZGRCdXR0b24pOwor
ICAgIGhpZGU6IGZ1bmN0aW9uKCkKKyAgICB7CisgICAgICAgIHRoaXMuX3Zpc2libGUgPSBmYWxz
ZTsKKyAgICB9LAogCi0gICAgICAgIHRoaXMub25leHBhbmQgPSB0aGlzLnJlZnJlc2hFeHByZXNz
aW9ucy5iaW5kKHRoaXMpOworICAgIHJlc2V0OiBmdW5jdGlvbigpCisgICAgeworICAgICAgICB0
aGlzLnJlZnJlc2hFeHByZXNzaW9ucygpOworICAgIH0sCisKKyAgICByZWZyZXNoRXhwcmVzc2lv
bnM6IGZ1bmN0aW9uKCkKKyAgICB7CisgICAgICAgIHRoaXMuX3JlcXVpcmVzVXBkYXRlID0gdHJ1
ZTsKKyAgICAgICAgdGhpcy5fcmVmcmVzaEV4cHJlc3Npb25zSWZOZWVkZWQoKTsKKyAgICB9LAor
CisgICAgX3JlZnJlc2hFeHByZXNzaW9uc0lmTmVlZGVkOiBmdW5jdGlvbigpCisgICAgeworICAg
ICAgICBpZiAodGhpcy5fcmVxdWlyZXNVcGRhdGUgJiYgdGhpcy5fdmlzaWJsZSkgeworICAgICAg
ICAgICAgdGhpcy5zZWN0aW9uLnVwZGF0ZSgpOworICAgICAgICAgICAgZGVsZXRlIHRoaXMuX3Jl
cXVpcmVzVXBkYXRlOworICAgICAgICB9IGVsc2UKKyAgICAgICAgICAgIHRoaXMuX3JlcXVpcmVz
VXBkYXRlID0gdHJ1ZTsKICAgICB9LAogCiAgICAgX2FkZEJ1dHRvbkNsaWNrZWQ6IGZ1bmN0aW9u
KGV2ZW50KQpAQCAtNjcsMTEgKzk2LDYgQEAgV2ViSW5zcGVjdG9yLldhdGNoRXhwcmVzc2lvbnNT
aWRlYmFyUGFuZS5wcm90b3R5cGUgPSB7CiAgICAgewogICAgICAgICBldmVudC5zdG9wUHJvcGFn
YXRpb24oKTsKICAgICAgICAgdGhpcy5yZWZyZXNoRXhwcmVzc2lvbnMoKTsKLSAgICB9LAotCi0g
ICAgcmVmcmVzaEV4cHJlc3Npb25zOiBmdW5jdGlvbigpCi0gICAgewotICAgICAgICB0aGlzLnNl
Y3Rpb24udXBkYXRlKCk7CiAgICAgfQogfQogCg==
</data>

          </attachment>
      

    </bug>

</bugzilla>