Bug 208150 - Crash in Document::dispatchDisabledAdaptationsDidChangeForMainFrame
Summary: Crash in Document::dispatchDisabledAdaptationsDidChangeForMainFrame
Status: NEW
Alias: None
Product: WebKit
Classification: Unclassified
Component: DOM (show other bugs)
Version: WebKit Nightly Build
Hardware: All All
: P2 Normal
Assignee: Nobody
URL:
Keywords: InRadar
Depends on:
Blocks:
 
Reported: 2020-02-24 12:26 PST by Pinki Gyanchandani
Modified: 2022-02-09 10:14 PST (History)
6 users (show)

See Also:


Attachments
Patch (6.24 KB, patch)
2020-02-24 13:51 PST, Pinki Gyanchandani
rniwa: review-
Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Pinki Gyanchandani 2020-02-24 12:26:08 PST
Initial crash is due to re-entrancy in function didBecomeCurrentDocumentInFrame. The re-entrancy was addressed with below change 

Style::PostResolutionCallbackDisabler disabler(*newDocument);
        WidgetHierarchyUpdatesSuspensionScope suspendWidgetHierarchyUpdates;
        ScriptDisallowedScope::InMainThread scriptDisallowedScope; 

But due to an orphan frame access later the crash was observed in initContentSecurityPolicy.
Comment 1 Pinki Gyanchandani 2020-02-24 13:51:29 PST
Created attachment 391574 [details]
Patch
Comment 2 Ryosuke Niwa 2020-02-24 19:31:57 PST
Ugh... looks like this patch broke WK1 :(
Comment 3 Ryosuke Niwa 2020-02-24 19:32:13 PST
Comment on attachment 391574 [details]
Patch

r- because tests are failing. We need to figure out why.
Comment 4 Ryosuke Niwa 2020-02-24 19:32:26 PST
<rdar://problem/57161887>