Bug 168608

Summary: Nullptr dereferences when stopping a load
Product: WebKit Reporter: Brent Fulgham <bfulgham>
Component: Page LoadingAssignee: Brent Fulgham <bfulgham>
Status: RESOLVED FIXED    
Severity: Normal CC: beidson, bfulgham, cdumez, commit-queue, dbates, ddkilzer, japhet, rniwa
Priority: P2 Keywords: InRadar
Version: WebKit Nightly Build   
Hardware: Unspecified   
OS: Unspecified   
Attachments:
Description Flags
Patch rniwa: review+

Brent Fulgham
Reported 2017-02-20 12:04:48 PST
We have seen crash traces that indicate the frame is being detached from the document while stopping a load, leading to nullptr dereferences and crashes. Other loading code anticipates the possibility the the frame is nullptr. Since these crashes are happening at the tail end of the load termination, when attempting to notify the now-detached client that the load was stopped, we should probably just recognize this is happening and avoid the dereference.
Attachments
Patch (3.09 KB, patch)
2017-02-20 12:09 PST, Brent Fulgham
rniwa: review+
Brent Fulgham
Comment 1 2017-02-20 12:09:06 PST
Ryosuke Niwa
Comment 2 2017-02-20 12:14:08 PST
Comment on attachment 302163 [details] Patch r=me. It's sad we can't have a test for this.
Brent Fulgham
Comment 3 2017-02-20 12:59:44 PST
Brent Fulgham
Comment 4 2017-02-20 13:00:52 PST
Note You need to log in before you can comment on or make changes to this bug.