<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>73939</bug_id>
          
          <creation_ts>2011-12-06 11:47:14 -0800</creation_ts>
          <short_desc>[chromium] Don&apos;t crash if tile upload happens without painting first</short_desc>
          <delta_ts>2011-12-06 14:26:49 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>New Bugs</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Adrienne Walker">enne</reporter>
          <assigned_to name="Adrienne Walker">enne</assigned_to>
          <cc>cc-bugs</cc>
    
    <cc>enne</cc>
    
    <cc>jamesr</cc>
    
    <cc>reveman</cc>
    
    <cc>vangelis</cc>
    
    <cc>webkit.review.bot</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>516104</commentid>
    <comment_count>0</comment_count>
    <who name="Adrienne Walker">enne</who>
    <bug_when>2011-12-06 11:47:14 -0800</bug_when>
    <thetext>[chromium] Don&apos;t crash if tile upload happens without painting first</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>516113</commentid>
    <comment_count>1</comment_count>
      <attachid>118084</attachid>
    <who name="Adrienne Walker">enne</who>
    <bug_when>2011-12-06 11:51:01 -0800</bug_when>
    <thetext>Created attachment 118084
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>516122</commentid>
    <comment_count>2</comment_count>
    <who name="Adrienne Walker">enne</who>
    <bug_when>2011-12-06 11:56:14 -0800</bug_when>
    <thetext>See: http://code.google.com/p/chromium/issues/detail?id=105569

I think this crash is caused by a paint/upload mismatch.  A layer isn&apos;t painted but is uploaded from, so its tiler isn&apos;t created.  I&apos;m not totally sure where this is happening, but that seems like a likely culprit.

The proper fix is the ForEachCompositorResource functor iteration from https://bugs.webkit.org/show_bug.cgi?id=72752, but I want something small that can be backported to m17.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>516136</commentid>
    <comment_count>3</comment_count>
    <who name="David Reveman">reveman</who>
    <bug_when>2011-12-06 12:09:01 -0800</bug_when>
    <thetext>Looks good to me. Any idea how we end up calling updateCompositorResources() without prepareToUpdate first?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>516137</commentid>
    <comment_count>4</comment_count>
    <who name="Adrienne Walker">enne</who>
    <bug_when>2011-12-06 12:16:32 -0800</bug_when>
    <thetext>(In reply to comment #3)
&gt; Looks good to me. Any idea how we end up calling updateCompositorResources() without prepareToUpdate first?

I&apos;m not totally sure, but there&apos;s two totally different code paths, so it seemed really plausible.

Actually, ImageLayerChromium::paintContentsIfDirty has an early out before prepareToUpdate if the visible rect is empty.  That would do it.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>516151</commentid>
    <comment_count>5</comment_count>
      <attachid>118090</attachid>
    <who name="Adrienne Walker">enne</who>
    <bug_when>2011-12-06 12:27:44 -0800</bug_when>
    <thetext>Created attachment 118090
Fix ImageLayerChromium to not do this</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>516154</commentid>
    <comment_count>6</comment_count>
      <attachid>118090</attachid>
    <who name="James Robinson">jamesr</who>
    <bug_when>2011-12-06 12:31:08 -0800</bug_when>
    <thetext>Comment on attachment 118090
Fix ImageLayerChromium to not do this

This looks safe</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>516253</commentid>
    <comment_count>7</comment_count>
      <attachid>118090</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-12-06 14:26:44 -0800</bug_when>
    <thetext>Comment on attachment 118090
Fix ImageLayerChromium to not do this

Clearing flags on attachment: 118090

Committed r102180: &lt;http://trac.webkit.org/changeset/102180&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>516254</commentid>
    <comment_count>8</comment_count>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-12-06 14:26:49 -0800</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>118084</attachid>
            <date>2011-12-06 11:51:01 -0800</date>
            <delta_ts>2011-12-06 12:27:41 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-73939-20111206115100.patch</filename>
            <type>text/plain</type>
            <size>1961</size>
            <attacher name="Adrienne Walker">enne</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTAxOTYyCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggZThjMjI5ZDE0Njc4NWJm
YmY0OTI2N2JiZmI3YjhiYjU4M2ZhN2FiZS4uN2EyZTBlZDY4ZTQwYWE0N2RhZTk2NzI3MjYwN2Ux
MmFmZGRjYzkyNyAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDE2IEBACisyMDExLTEyLTA2ICBBZHJp
ZW5uZSBXYWxrZXIgIDxlbm5lQGdvb2dsZS5jb20+CisKKyAgICAgICAgW2Nocm9taXVtXSBEb24n
dCBjcmFzaCBpZiB0aWxlIHVwbG9hZCBoYXBwZW5zIHdpdGhvdXQgcGFpbnRpbmcgZmlyc3QKKyAg
ICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTczOTM5CisKKyAg
ICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAgICAgQWx0aG91Z2ggdGhp
cyBzaG91bGRuJ3QgaGFwcGVuLCB3ZSBzaG91bGQgYmUgcm9idXN0IHRvIGl0IGluIHRoZQorICAg
ICAgICBjaGFuY2UgdGhhdCBvdGhlciBjb2RlIGNhdXNlcyBpdCB0by4KKworICAgICAgICAqIHBs
YXRmb3JtL2dyYXBoaWNzL2Nocm9taXVtL1RpbGVkTGF5ZXJDaHJvbWl1bS5jcHA6CisgICAgICAg
IChXZWJDb3JlOjpUaWxlZExheWVyQ2hyb21pdW06OnVwZGF0ZUNvbXBvc2l0b3JSZXNvdXJjZXMp
OgorCiAyMDExLTEyLTA0ICBBbmRyZWFzIEtsaW5nICA8a2xpbmdAd2Via2l0Lm9yZz4KIAogICAg
ICAgICBDU1NWYWx1ZVBvb2w6IElubGluZSB0cml2aWFsIGdldHRlcnMuCmRpZmYgLS1naXQgYS9T
b3VyY2UvV2ViQ29yZS9wbGF0Zm9ybS9ncmFwaGljcy9jaHJvbWl1bS9UaWxlZExheWVyQ2hyb21p
dW0uY3BwIGIvU291cmNlL1dlYkNvcmUvcGxhdGZvcm0vZ3JhcGhpY3MvY2hyb21pdW0vVGlsZWRM
YXllckNocm9taXVtLmNwcAppbmRleCA5NjhkOWUzZTRhY2U2NTAxMGM4M2RkYzlkODg0Y2NiYTkx
YjAyNWUxLi41YzU1ZjU5YmYzZTczNzJmZTllYzUxMmVmNjM2MTEwMWFjNWEwNWU1IDEwMDY0NAot
LS0gYS9Tb3VyY2UvV2ViQ29yZS9wbGF0Zm9ybS9ncmFwaGljcy9jaHJvbWl1bS9UaWxlZExheWVy
Q2hyb21pdW0uY3BwCisrKyBiL1NvdXJjZS9XZWJDb3JlL3BsYXRmb3JtL2dyYXBoaWNzL2Nocm9t
aXVtL1RpbGVkTGF5ZXJDaHJvbWl1bS5jcHAKQEAgLTE3NCw4ICsxNzQsMTIgQEAgdm9pZCBUaWxl
ZExheWVyQ2hyb21pdW06OmNyZWF0ZVRpbGVyKENDTGF5ZXJUaWxpbmdEYXRhOjpCb3JkZXJUZXhl
bE9wdGlvbiBib3JkZXIKIAogdm9pZCBUaWxlZExheWVyQ2hyb21pdW06OnVwZGF0ZUNvbXBvc2l0
b3JSZXNvdXJjZXMoR3JhcGhpY3NDb250ZXh0M0QqLCBDQ1RleHR1cmVVcGRhdGVyJiB1cGRhdGVy
KQogeworICAgIC8vIElmIHRoaXMgYXNzZXJ0IGlzIGhpdCwgaXQgbWVhbnMgdGhhdCBwYWludENv
bnRlbnRzSWZEaXJ0eSBoYXNuJ3QgYmVlbgorICAgIC8vIGNhbGxlZCBvbiB0aGlzIGxheWVyLiBB
bnkgbGF5ZXIgdGhhdCBpcyB1cGRhdGVkIHNob3VsZCBiZSBwYWludGVkIGZpcnN0LgorICAgIEFT
U0VSVChtX3RpbGVyKTsKKwogICAgIC8vIFBhaW50aW5nIGNvdWxkIGNhdXNlIGNvbXBvc2l0aW5n
IHRvIGdldCB0dXJuZWQgb2ZmLCB3aGljaCBtYXkgY2F1c2UgdGhlIHRpbGVyIHRvIGJlY29tZSBp
bnZhbGlkYXRlZCBtaWQtdXBkYXRlLgotICAgIGlmIChtX3NraXBzRHJhdyB8fCBtX3JlcXVlc3Rl
ZFVwZGF0ZVJlY3QuaXNFbXB0eSgpIHx8ICFtX3RpbGVyLT5udW1UaWxlcygpKQorICAgIGlmICht
X3NraXBzRHJhdyB8fCBtX3JlcXVlc3RlZFVwZGF0ZVJlY3QuaXNFbXB0eSgpIHx8ICFtX3RpbGVy
IHx8ICFtX3RpbGVyLT5udW1UaWxlcygpKQogICAgICAgICByZXR1cm47CiAKICAgICBpbnQgbGVm
dCwgdG9wLCByaWdodCwgYm90dG9tOwo=
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>118090</attachid>
            <date>2011-12-06 12:27:44 -0800</date>
            <delta_ts>2011-12-06 14:26:44 -0800</delta_ts>
            <desc>Fix ImageLayerChromium to not do this</desc>
            <filename>bug-73939-20111206122743.patch</filename>
            <type>text/plain</type>
            <size>2756</size>
            <attacher name="Adrienne Walker">enne</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTAxOTYyCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggZThjMjI5ZDE0Njc4NWJm
YmY0OTI2N2JiZmI3YjhiYjU4M2ZhN2FiZS4uOWYzOGYyZmU2NmM5NDI5OGYwOTZkMmU4Y2ZkYmMw
YzIxZWExZjNiYyAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDIxIEBACisyMDExLTEyLTA2ICBBZHJp
ZW5uZSBXYWxrZXIgIDxlbm5lQGdvb2dsZS5jb20+CisKKyAgICAgICAgW2Nocm9taXVtXSBEb24n
dCBjcmFzaCBpZiB0aWxlIHVwbG9hZCBoYXBwZW5zIHdpdGhvdXQgcGFpbnRpbmcgZmlyc3QKKyAg
ICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTczOTM5CisKKyAg
ICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAgICAgUmVtb3ZlIGF0IGxl
YXN0IG9uZSBwbGFjZSAoaW4gSW1hZ2VMYXllckNocm9taXVtKSB3aGVyZSB0aGlzIGNvdWxkCisg
ICAgICAgIGhhcHBlbi4KKworICAgICAgICBBbHRob3VnaCB0aGlzIHNob3VsZG4ndCBoYXBwZW4s
IHdlIHNob3VsZCBiZSByb2J1c3QgdG8gaXQgaW4gdGhlCisgICAgICAgIGNoYW5jZSB0aGF0IG90
aGVyIGNvZGUgY2F1c2VzIGl0IHRvLgorCisgICAgICAgICogcGxhdGZvcm0vZ3JhcGhpY3MvY2hy
b21pdW0vSW1hZ2VMYXllckNocm9taXVtLmNwcDoKKyAgICAgICAgKFdlYkNvcmU6OkltYWdlTGF5
ZXJDaHJvbWl1bTo6cGFpbnRDb250ZW50c0lmRGlydHkpOgorICAgICAgICAqIHBsYXRmb3JtL2dy
YXBoaWNzL2Nocm9taXVtL1RpbGVkTGF5ZXJDaHJvbWl1bS5jcHA6CisgICAgICAgIChXZWJDb3Jl
OjpUaWxlZExheWVyQ2hyb21pdW06OnVwZGF0ZUNvbXBvc2l0b3JSZXNvdXJjZXMpOgorCiAyMDEx
LTEyLTA0ICBBbmRyZWFzIEtsaW5nICA8a2xpbmdAd2Via2l0Lm9yZz4KIAogICAgICAgICBDU1NW
YWx1ZVBvb2w6IElubGluZSB0cml2aWFsIGdldHRlcnMuCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2Vi
Q29yZS9wbGF0Zm9ybS9ncmFwaGljcy9jaHJvbWl1bS9JbWFnZUxheWVyQ2hyb21pdW0uY3BwIGIv
U291cmNlL1dlYkNvcmUvcGxhdGZvcm0vZ3JhcGhpY3MvY2hyb21pdW0vSW1hZ2VMYXllckNocm9t
aXVtLmNwcAppbmRleCA3MGFmZGQwODJjNDNmYzAyODljYTkwMjliOTY0YTRkNDRlMzQ0ZTczLi5h
MWFjNDdmNDFiMGNlZDgxOWU2MWY3MGVkNGUwN2Y3Yzk4ZjQ2OTk2IDEwMDY0NAotLS0gYS9Tb3Vy
Y2UvV2ViQ29yZS9wbGF0Zm9ybS9ncmFwaGljcy9jaHJvbWl1bS9JbWFnZUxheWVyQ2hyb21pdW0u
Y3BwCisrKyBiL1NvdXJjZS9XZWJDb3JlL3BsYXRmb3JtL2dyYXBoaWNzL2Nocm9taXVtL0ltYWdl
TGF5ZXJDaHJvbWl1bS5jcHAKQEAgLTE3OSw5ICsxNzksNiBAQCB2b2lkIEltYWdlTGF5ZXJDaHJv
bWl1bTo6cGFpbnRDb250ZW50c0lmRGlydHkoKQogICAgICAgICB9CiAgICAgfQogCi0gICAgaWYg
KHZpc2libGVMYXllclJlY3QoKS5pc0VtcHR5KCkpCi0gICAgICAgIHJldHVybjsKLQogICAgIHBy
ZXBhcmVUb1VwZGF0ZSh2aXNpYmxlTGF5ZXJSZWN0KCkpOwogfQogCmRpZmYgLS1naXQgYS9Tb3Vy
Y2UvV2ViQ29yZS9wbGF0Zm9ybS9ncmFwaGljcy9jaHJvbWl1bS9UaWxlZExheWVyQ2hyb21pdW0u
Y3BwIGIvU291cmNlL1dlYkNvcmUvcGxhdGZvcm0vZ3JhcGhpY3MvY2hyb21pdW0vVGlsZWRMYXll
ckNocm9taXVtLmNwcAppbmRleCA5NjhkOWUzZTRhY2U2NTAxMGM4M2RkYzlkODg0Y2NiYTkxYjAy
NWUxLi41YzU1ZjU5YmYzZTczNzJmZTllYzUxMmVmNjM2MTEwMWFjNWEwNWU1IDEwMDY0NAotLS0g
YS9Tb3VyY2UvV2ViQ29yZS9wbGF0Zm9ybS9ncmFwaGljcy9jaHJvbWl1bS9UaWxlZExheWVyQ2hy
b21pdW0uY3BwCisrKyBiL1NvdXJjZS9XZWJDb3JlL3BsYXRmb3JtL2dyYXBoaWNzL2Nocm9taXVt
L1RpbGVkTGF5ZXJDaHJvbWl1bS5jcHAKQEAgLTE3NCw4ICsxNzQsMTIgQEAgdm9pZCBUaWxlZExh
eWVyQ2hyb21pdW06OmNyZWF0ZVRpbGVyKENDTGF5ZXJUaWxpbmdEYXRhOjpCb3JkZXJUZXhlbE9w
dGlvbiBib3JkZXIKIAogdm9pZCBUaWxlZExheWVyQ2hyb21pdW06OnVwZGF0ZUNvbXBvc2l0b3JS
ZXNvdXJjZXMoR3JhcGhpY3NDb250ZXh0M0QqLCBDQ1RleHR1cmVVcGRhdGVyJiB1cGRhdGVyKQog
eworICAgIC8vIElmIHRoaXMgYXNzZXJ0IGlzIGhpdCwgaXQgbWVhbnMgdGhhdCBwYWludENvbnRl
bnRzSWZEaXJ0eSBoYXNuJ3QgYmVlbgorICAgIC8vIGNhbGxlZCBvbiB0aGlzIGxheWVyLiBBbnkg
bGF5ZXIgdGhhdCBpcyB1cGRhdGVkIHNob3VsZCBiZSBwYWludGVkIGZpcnN0LgorICAgIEFTU0VS
VChtX3RpbGVyKTsKKwogICAgIC8vIFBhaW50aW5nIGNvdWxkIGNhdXNlIGNvbXBvc2l0aW5nIHRv
IGdldCB0dXJuZWQgb2ZmLCB3aGljaCBtYXkgY2F1c2UgdGhlIHRpbGVyIHRvIGJlY29tZSBpbnZh
bGlkYXRlZCBtaWQtdXBkYXRlLgotICAgIGlmIChtX3NraXBzRHJhdyB8fCBtX3JlcXVlc3RlZFVw
ZGF0ZVJlY3QuaXNFbXB0eSgpIHx8ICFtX3RpbGVyLT5udW1UaWxlcygpKQorICAgIGlmIChtX3Nr
aXBzRHJhdyB8fCBtX3JlcXVlc3RlZFVwZGF0ZVJlY3QuaXNFbXB0eSgpIHx8ICFtX3RpbGVyIHx8
ICFtX3RpbGVyLT5udW1UaWxlcygpKQogICAgICAgICByZXR1cm47CiAKICAgICBpbnQgbGVmdCwg
dG9wLCByaWdodCwgYm90dG9tOwo=
</data>

          </attachment>
      

    </bug>

</bugzilla>