Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge r186666 - Plugin create can end up destroying its renderer.
https://bugs.webkit.org/show_bug.cgi?id=146824 rdar://problem/18921429 Reviewed by Andreas Kling. Plugins can run arbitrary code during initialization. If the plugin happens to destroy the associated node, its renderer becomes invalid. This patch checks whether the renderer survived the createPlugin() call. (This WeakPtr pattern is also used in RenderWidget to avoid dangling pointers.) Speculative fix. Not reproducible. * loader/SubframeLoader.cpp: (WebCore::SubframeLoader::loadPlugin):
- Loading branch information
1 parent
689d979
commit 4bc8b58
Showing
2 changed files
with
26 additions
and
2 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters