Bug 113369 - [BlackBerry] Assert failure when destructing DumpRenderTree
Summary: [BlackBerry] Assert failure when destructing DumpRenderTree
Status: CLOSED DUPLICATE of bug 114503
Alias: None
Product: WebKit
Classification: Unclassified
Component: WebKit BlackBerry (show other bugs)
Version: 528+ (Nightly build)
Hardware: Other Other
: P2 Normal
Assignee: Nobody
Depends on:
Reported: 2013-03-27 00:55 PDT by Xiaobo Wang
Modified: 2013-05-09 10:53 PDT (History)
4 users (show)

See Also:

patch (6.12 KB, patch)
2013-03-27 01:30 PDT, Xiaobo Wang
rwlbuis: review-
Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Xiaobo Wang 2013-03-27 00:55:40 PDT
RIM PR 316822

Back traces
#0  0x7817d142 in BlackBerry::Platform::platformCrash (file=0x78338fa8
    line=<optimized out>, function=<optimized out>) at
#1  0x78186c8c in BlackBerry::Platform::GuardedPointerBase::~GuardedPointerBase
(this=0x816426c, __in_chrg=<optimized out>)
#2  0x782d97b4 in BlackBerry::Platform::LayoutTestClient::~LayoutTestClient
(this=0x816426c, __in_chrg=<optimized out>)
#3  0x784c5a5a in ~Timer (this=0x81642f0, __in_chrg=<optimized out>) at
#4  BlackBerry::WebKit::DumpRenderTree::~DumpRenderTree (this=0x8164268,
__in_chrg=<optimized out>)
#5  0x784c5ac8 in destruct (end=0x0, begin=0x0) at
#6  destruct (end=0x0, begin=0x0) at
#7  shrink (this=0x8164278, size=<optimized out>) at
#8  ~Vector (this=0x8164278, __in_chrg=<optimized out>) at
#9  BlackBerry::WebKit::DumpRenderTree::~DumpRenderTree (this=0x8164268,
__in_chrg=<optimized out>)
#10 0x080980c8 in ?? ()
#11 0x080980c8 in ?? ()

Root cause
B::W::DumpRenderTree derived from B::W::DumpRenderTreeClient and
B::P::LayoutTestClient, and B::P::LayoutTestClient derived from
In WebPagePrivate::m_dumpRenderTree is a B::W::DumpRenderTreeClient pointer
backed by a B::W::DumpRenderTree instance. So if we delete m_dumpRenderTree the
DumpRenderTree object will be deleted directory without calling
deleteGuardedObject, and hit the assert in

Since WebPagePrivate::m_dumpRenderTree is not derived from GuardedPointerBase,
we can't use "deleteGuardedObject(m_dumpRenderTree);". We can add a virtual
function DumpRenderTreeClient::destroy() and use it to destruct the
DumpRenderTree instance.
Comment 1 Xiaobo Wang 2013-03-27 01:30:52 PDT
Created attachment 195241 [details]
Comment 2 Xiaobo Wang 2013-04-14 20:13:12 PDT
Fixed in another bug https://bugs.webkit.org/show_bug.cgi?id=114503
 by Carlos Garcia Campos. So close this one for now.

*** This bug has been marked as a duplicate of bug 114503 ***
Comment 3 Xiaobo Wang 2013-04-14 20:14:18 PDT
Comment 4 Rob Buis 2013-05-09 10:53:09 PDT
Comment on attachment 195241 [details]

This was fixed in a different way, internal commit webkit/92b8ab4cf0514289f6114dd39c3944115ce5e72b.