Bug 55958

Summary: Crash in CFNetwork visiting google.com
Product: WebKit Reporter: Jessie Berlin <jberlin>
Component: WebKit2Assignee: Jessie Berlin <jberlin>
Status: RESOLVED FIXED    
Severity: Normal CC: andersca, aroben, jberlin, sam
Priority: P2 Keywords: InRadar, PlatformOnly
Version: 528+ (Nightly build)   
Hardware: All   
OS: Windows 7   
Attachments:
Description Flags
Patch
none
Patch with a test none

Jessie Berlin
Reported 2011-03-08 12:04:34 PST
The crash occurs when trying to copy a CFURLResponseRef in WKURLResponseCopyCFURLResponse that is null underneath WebCore::MainResourceLoader::handleEmptyLoad. Since the load is empty, it is reasonable for the CFURLResponseRef to be null, and we should not try to copy a null CFURLResponseRef. <rdar://problem/9102016>
Attachments
Patch (1.32 KB, patch)
2011-03-08 12:15 PST, Jessie Berlin
no flags
Patch with a test (5.40 KB, patch)
2011-03-08 13:24 PST, Jessie Berlin
no flags
Jessie Berlin
Comment 1 2011-03-08 12:15:44 PST
Jessie Berlin
Comment 2 2011-03-08 13:24:25 PST
Created attachment 85085 [details] Patch with a test
Jessie Berlin
Comment 3 2011-03-08 13:44:08 PST
Adam Roben (:aroben)
Comment 4 2011-03-08 14:17:39 PST
Comment on attachment 85085 [details] Patch with a test View in context: https://bugs.webkit.org/attachment.cgi?id=85085&action=review > Tools/TestWebKitAPI/Tests/WebKit2/win/DoNotCopyANullCFURLResponse.cpp:38 > + WKRetainPtr<WKURLResponseRef> nullWKResponse = WKURLResponseCreateWithCFURLResponse(0); > + RetainPtr<CFURLResponseRef> nullCFResponse = WKURLResponseCopyCFURLResponse(kCFAllocatorDefault, nullWKResponse.get()); Both of these are being leaked.
Jessie Berlin
Comment 5 2011-03-08 15:44:09 PST
(In reply to comment #4) > (From update of attachment 85085 [details]) > View in context: https://bugs.webkit.org/attachment.cgi?id=85085&action=review > > > Tools/TestWebKitAPI/Tests/WebKit2/win/DoNotCopyANullCFURLResponse.cpp:38 > > + WKRetainPtr<WKURLResponseRef> nullWKResponse = WKURLResponseCreateWithCFURLResponse(0); > > + RetainPtr<CFURLResponseRef> nullCFResponse = WKURLResponseCopyCFURLResponse(kCFAllocatorDefault, nullWKResponse.get()); > > Both of these are being leaked. Fixed in r80599 http://trac.webkit.org/changeset/80599
Note You need to log in before you can comment on or make changes to this bug.