Summary: | [GPUProcess] Crash in SharedRingBufferStorage::setStorage() under GuardMalloc | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Chris Dumez <cdumez> | ||||||||||
Component: | WebAssembly | Assignee: | Chris Dumez <cdumez> | ||||||||||
Status: | RESOLVED FIXED | ||||||||||||
Severity: | Normal | CC: | darin, eric.carlson, ews-watchlist, ggaren, glenn, jer.noble, peng.liu6, philipj, sergio, webkit-bug-importer, youennf | ||||||||||
Priority: | P2 | Keywords: | InRadar | ||||||||||
Version: | WebKit Nightly Build | ||||||||||||
Hardware: | Unspecified | ||||||||||||
OS: | Unspecified | ||||||||||||
See Also: | https://bugs.webkit.org/show_bug.cgi?id=219859 | ||||||||||||
Bug Depends on: | |||||||||||||
Bug Blocks: | 219818 | ||||||||||||
Attachments: |
|
Description
Chris Dumez
2020-12-14 11:38:39 PST
Created attachment 416183 [details]
Patch
Created attachment 416185 [details]
Patch
Comment on attachment 416185 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=416185&action=review > Source/WebKit/GPUProcess/media/RemoteAudioSourceProviderProxy.cpp:64 > + auto ringBuffer = makeUniqueRef<CARingBuffer>(makeUniqueRef<SharedRingBufferStorage>([this, protectedThis = makeRef(*this)](SharedMemory* memory) mutable { > + storageChanged(memory); > + })); I might have written: protectedThis->storageChanged(memory); And then not captured "this". Created attachment 416186 [details]
Patch
(In reply to Darin Adler from comment #3) > Comment on attachment 416185 [details] > Patch > > View in context: > https://bugs.webkit.org/attachment.cgi?id=416185&action=review > > > Source/WebKit/GPUProcess/media/RemoteAudioSourceProviderProxy.cpp:64 > > + auto ringBuffer = makeUniqueRef<CARingBuffer>(makeUniqueRef<SharedRingBufferStorage>([this, protectedThis = makeRef(*this)](SharedMemory* memory) mutable { > > + storageChanged(memory); > > + })); > > I might have written: > > protectedThis->storageChanged(memory); > > And then not captured "this". Done. Comment on attachment 416186 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=416186&action=review > Source/WebKit/ChangeLog:15 > + of the CARingBuffer is not tried to the lifetime of RemoteAudioSourceProviderProxy. Nit. s/tried/tied/ Created attachment 416190 [details]
Patch
Committed r270804: <https://trac.webkit.org/changeset/270804> All reviewed patches have been landed. Closing bug and clearing flags on attachment 416190 [details]. |