WebKit Bugzilla
New
Browse
Log In
×
Sign in with GitHub
or
Remember my login
Create Account
·
Forgot Password
Forgotten password account recovery
RESOLVED DUPLICATE of
bug 114521
114488
REGRESSION(
r147942
): Potentially lots of crashes while updating widget hierarchy
https://bugs.webkit.org/show_bug.cgi?id=114488
Summary
REGRESSION(r147942): Potentially lots of crashes while updating widget hierarchy
Ryosuke Niwa
Reported
2013-04-11 20:39:06 PDT
See
https://codereview.chromium.org/14218002/
. We need to merge this Blink change back.
Attachments
Patch
(8.42 KB, patch)
2013-04-12 10:05 PDT
,
Andrei Bucur
andersca
: review+
Details
Formatted Diff
Diff
View All
Add attachment
proposed patch, testcase, etc.
Ryosuke Niwa
Comment 1
2013-04-11 21:59:28 PDT
esprehn: rniwa: I'd suggest rolling out
r148092
,
r148026
and
r147942
esprehn: unless you think you can fix removeChildren to be safe
Andrei Bucur
Comment 2
2013-04-11 23:59:33 PDT
Working on it. Hopefully I can find a proper fix by tomorrow morning your time. Otherwise I'll do the rollbacks.
Andrei Bucur
Comment 3
2013-04-12 04:17:48 PDT
This is the call stack causing the use after free: #0 0x000000010cc8da1e in WebCore::ScrollView::~ScrollView() at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/platform/ScrollView.cpp:66 #1 0x000000010bc0d10d in WebCore::FrameView::~FrameView() at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/page/FrameView.cpp:261 #2 0x000000010bc0cbe5 in WebCore::FrameView::~FrameView() at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/page/FrameView.cpp:236 #3 0x000000010bc0cbb9 in WebCore::FrameView::~FrameView() at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/page/FrameView.cpp:236 #4 0x000000010b4d84e3 in WTF::RefCounted<WebCore::Widget>::deref() at /Volumes/HDD/NonPerforce/WebKit/WebKitBuild/b114488/Debug/usr/local/include/wtf/RefCounted.h:202 #5 0x000000010b61625b in void WTF::derefIfNotNull<WebCore::FrameView>(WebCore::FrameView*) at /Volumes/HDD/NonPerforce/WebKit/WebKitBuild/b114488/Debug/usr/local/include/wtf/PassRefPtr.h:53 #6 0x000000010bbd8ed8 in WTF::RefPtr<WebCore::FrameView>::operator=(WTF::PassRefPtr<WebCore::FrameView> const&) at /Volumes/HDD/NonPerforce/WebKit/WebKitBuild/b114488/Debug/usr/local/include/wtf/RefPtr.h:134 #7 0x000000010bbd5085 in WebCore::Frame::setView(WTF::PassRefPtr<WebCore::FrameView>) at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/page/Frame.cpp:268 #8 0x000000010bbedef1 in WebCore::FrameLoader::closeAndRemoveChild(WebCore::Frame*) at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/loader/FrameLoader.cpp:2318 #9 0x000000010bbede25 in WebCore::FrameLoader::detachFromParent() at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/loader/FrameLoader.cpp:2398 #10 0x000000010bbee147 in WebCore::FrameLoader::frameDetached() at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/loader/FrameLoader.cpp:2376 #11 0x000000010bdafdd5 in WebCore::HTMLFrameOwnerElement::disconnectContentFrame() at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/html/HTMLFrameOwnerElement.cpp:84 #12 0x000000010b6e3497 in WebCore::ChildFrameDisconnector::disconnectCollectedFrameOwners() at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/dom/ContainerNodeAlgorithms.h:316 #13 0x000000010b6e06b1 in WebCore::ChildFrameDisconnector::disconnect(WebCore::ChildFrameDisconnector::DisconnectPolicy) at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/dom/ContainerNodeAlgorithms.h:336 #14 0x000000010b6dd75a in WebCore::ContainerNode::removeChildren() at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/dom/ContainerNode.cpp:596 #15 0x000000010c707476 in WebCore::replaceChildrenWithFragment(WebCore::ContainerNode*, WTF::PassRefPtr<WebCore::DocumentFragment>, int&) at /Volumes/HDD/NonPerforce/WebKit/Source/WebCore/editing/markup.cpp:1110 At first sight, it seems one of the children of the ScrollView is not properly reparented before the ScrollView is destroyed. I'll keep investigating.
Andrei Bucur
Comment 4
2013-04-12 10:05:52 PDT
Created
attachment 197863
[details]
Patch
Ryosuke Niwa
Comment 5
2013-04-12 15:41:05 PDT
***
Bug 114413
has been marked as a duplicate of this bug. ***
Tim Horton
Comment 6
2013-04-16 17:43:54 PDT
<
rdar://problem/13632610
>
Ryosuke Niwa
Comment 7
2013-04-16 18:12:56 PDT
*** This bug has been marked as a duplicate of
bug 114521
***
Note
You need to
log in
before you can comment on or make changes to this bug.
Top of Page
Format For Printing
XML
Clone This Bug