Bug 64656 - SubresourceLoader::didReceiveDataArray can crash when calling m_client->didReceiveData()
Summary: SubresourceLoader::didReceiveDataArray can crash when calling m_client->didRe...
Alias: None
Product: WebKit
Classification: Unclassified
Component: Platform (show other bugs)
Version: 528+ (Nightly build)
Hardware: Unspecified Unspecified
: P2 Normal
Assignee: Pratik Solanki
Keywords: InRadar
Depends on:
Reported: 2011-07-16 15:00 PDT by Pratik Solanki
Modified: 2011-07-16 16:29 PDT (History)
1 user (show)

See Also:

Patch (1.61 KB, patch)
2011-07-16 15:14 PDT, Pratik Solanki
ap: review+
ap: commit-queue-
Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Pratik Solanki 2011-07-16 15:00:33 PDT
SubresourceLoader::didReceiveDataArray() calls m_client->didReceiveData() in a  loop. This can crash if m_client is deleted in an iteration. This is similar to bug 60594.
Comment 1 Pratik Solanki 2011-07-16 15:01:14 PDT
Comment 2 Pratik Solanki 2011-07-16 15:14:40 PDT
Created attachment 101101 [details]
Comment 3 Alexey Proskuryakov 2011-07-16 15:23:35 PDT
Comment on attachment 101101 [details]

View in context: https://bugs.webkit.org/attachment.cgi?id=101101&action=review

> Source/WebCore/loader/cf/SubresourceLoaderCF.cpp:47
> +            if (!m_client)
> +                break;

Please remove a check for m_client that you have above (if (!m_loadingMultipartContent && m_client)).
Comment 4 Pratik Solanki 2011-07-16 16:29:54 PDT
Committed r91157: <http://trac.webkit.org/changeset/91157>