WebKit Bugzilla
New
Browse
Log In
×
Sign in with GitHub
or
Remember my login
Create Account
·
Forgot Password
Forgotten password account recovery
RESOLVED FIXED
168608
Nullptr dereferences when stopping a load
https://bugs.webkit.org/show_bug.cgi?id=168608
Summary
Nullptr dereferences when stopping a load
Brent Fulgham
Reported
2017-02-20 12:04:48 PST
We have seen crash traces that indicate the frame is being detached from the document while stopping a load, leading to nullptr dereferences and crashes. Other loading code anticipates the possibility the the frame is nullptr. Since these crashes are happening at the tail end of the load termination, when attempting to notify the now-detached client that the load was stopped, we should probably just recognize this is happening and avoid the dereference.
Attachments
Patch
(3.09 KB, patch)
2017-02-20 12:09 PST
,
Brent Fulgham
rniwa
: review+
Details
Formatted Diff
Diff
View All
Add attachment
proposed patch, testcase, etc.
Brent Fulgham
Comment 1
2017-02-20 12:09:06 PST
Created
attachment 302163
[details]
Patch
Ryosuke Niwa
Comment 2
2017-02-20 12:14:08 PST
Comment on
attachment 302163
[details]
Patch r=me. It's sad we can't have a test for this.
Brent Fulgham
Comment 3
2017-02-20 12:59:44 PST
Committed
r212667
: <
http://trac.webkit.org/changeset/212667
>
Brent Fulgham
Comment 4
2017-02-20 13:00:52 PST
<
rdar://problem/29852056
>
Note
You need to
log in
before you can comment on or make changes to this bug.
Top of Page
Format For Printing
XML
Clone This Bug