Summary: | [WinCairo][WebKitTestRunner] Null dereference of GraphicsContext::m_data in GraphicsContext::releaseWindowsContext | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Fujii Hironori <Hironori.Fujii> | ||||||
Component: | Tools / Tests | Assignee: | Fujii Hironori <Hironori.Fujii> | ||||||
Status: | RESOLVED FIXED | ||||||||
Severity: | Normal | CC: | achristensen, bfulgham, don.olmstead, lforschler, pvollan, ross.kirsling, webkit-bug-importer | ||||||
Priority: | P2 | Keywords: | InRadar | ||||||
Version: | WebKit Nightly Build | ||||||||
Hardware: | Unspecified | ||||||||
OS: | Unspecified | ||||||||
Attachments: |
|
Description
Fujii Hironori
2019-01-22 00:23:15 PST
This can be happen by openning the test case with MiniBrowser. It doesn't happen in Legacy WebView (DumpRenderTree and MiniBrowser.exe --wk1). This happens only with WK2 WebView. In RenderThemeWin::paintMeter, completedRect has zero width. > completedRect {m_location={m_x=8 m_y=7 } m_size={m_width=0 m_height=16 } } WebCore::IntRect Then, GraphicsContext::getWindowsContext returned 0. https://github.com/WebKit/webkit/blob/5f7dcb377532103d4561192cd2197de0bd78c372/Source/WebCore/platform/graphics/win/GraphicsContextWin.cpp#L110 Then, LocalWindowsContext::~LocalWindowsContext tried to release zero HDC, and crashed. Created attachment 359726 [details]
Patch
Comment on attachment 359726 [details]
Patch
Seems reasonable. r=me.
Thank you for r+. Landed. https://trac.webkit.org/changeset/240313/webkit Reopening to attach new patch. Created attachment 359997 [details]
Patch
Comment on attachment 359997 [details]
Patch
Oops, I uploaded wrong patch.
|