You need to
before you can comment on or make changes to this bug.
DirectoryEntry's custom code added by issue 45724 for FileSystem API has wrong RefPtr handling.
When the given flags argument is an instance of Flags object, the custom code calls adoptRef to get a RefPtr from a raw Flags pointer returned by toFlags/toNative.
However, toFlags/toNative returns an already adopted pointer so it should just assign the returned pointer rather than adopt assignment (the latter doesn't increment refCount).
Created an attachment (id=67997) [details]
(From update of attachment 67997 [details])
toFlags() returns a ref-counted object, because WebCore::Flags is ref-counted, right? if this is correct, it might be nice to mention this in the ChangeLog file (to make sure we don't copy-paste this code for some other class, and automatically assume that toNewClass() will be ref-counted too, when it might not be).
Committed r68105: <http://trac.webkit.org/changeset/68105>