<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[206048] trunk/Source/WebCore</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://trac.webkit.org/projects/webkit/changeset/206048">206048</a></dd>
<dt>Author</dt> <dd>bfulgham@apple.com</dd>
<dt>Date</dt> <dd>2016-09-16 14:20:23 -0700 (Fri, 16 Sep 2016)</dd>
</dl>

<h3>Log Message</h3>
<pre>CaptionUserPreferences's use of the PageGroup's page map is incorrect
https://bugs.webkit.org/show_bug.cgi?id=122194
&lt;rdar://problem/27332004&gt;

Reviewed by Zalan Bujtas.

Avoid the possibility of dereferencing an unsafe iterator by checking
for an empty HashSet before using the result of 'begin()'.

No new tests because there is no change in behavior.

* page/CaptionUserPreferences.cpp:
(WebCore::CaptionUserPreferences::CaptionUserPreferences): Use new safer
accessor to retrieve the current page.
(WebCore::CaptionUserPreferences::setCaptionDisplayMode): Ditto.
(WebCore::CaptionUserPreferences::currentPage): Added.
(WebCore::CaptionUserPreferences::userPrefersCaptions): Use new safer
accessor to retrieve the current page.
(WebCore::CaptionUserPreferences::setUserPrefersCaptions): Ditto.
(WebCore::CaptionUserPreferences::userPrefersSubtitles): Ditto.
(WebCore::CaptionUserPreferences::setUserPrefersSubtitles): Ditto.
(WebCore::CaptionUserPreferences::userPrefersTextDescriptions): Ditto.
(WebCore::CaptionUserPreferences::setUserPrefersTextDescriptions): Ditto.
* page/CaptionUserPreferences.h:</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunkSourceWebCoreChangeLog">trunk/Source/WebCore/ChangeLog</a></li>
<li><a href="#trunkSourceWebCorepageCaptionUserPreferencescpp">trunk/Source/WebCore/page/CaptionUserPreferences.cpp</a></li>
<li><a href="#trunkSourceWebCorepageCaptionUserPreferencesh">trunk/Source/WebCore/page/CaptionUserPreferences.h</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunkSourceWebCoreChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/Source/WebCore/ChangeLog (206047 => 206048)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/WebCore/ChangeLog        2016-09-16 21:17:33 UTC (rev 206047)
+++ trunk/Source/WebCore/ChangeLog        2016-09-16 21:20:23 UTC (rev 206048)
</span><span class="lines">@@ -1,3 +1,30 @@
</span><ins>+2016-09-16  Brent Fulgham  &lt;bfulgham@apple.com&gt;
+
+        CaptionUserPreferences's use of the PageGroup's page map is incorrect
+        https://bugs.webkit.org/show_bug.cgi?id=122194
+        &lt;rdar://problem/27332004&gt;
+
+        Reviewed by Zalan Bujtas.
+
+        Avoid the possibility of dereferencing an unsafe iterator by checking
+        for an empty HashSet before using the result of 'begin()'.
+
+        No new tests because there is no change in behavior.
+
+        * page/CaptionUserPreferences.cpp:
+        (WebCore::CaptionUserPreferences::CaptionUserPreferences): Use new safer
+        accessor to retrieve the current page.
+        (WebCore::CaptionUserPreferences::setCaptionDisplayMode): Ditto.
+        (WebCore::CaptionUserPreferences::currentPage): Added.
+        (WebCore::CaptionUserPreferences::userPrefersCaptions): Use new safer
+        accessor to retrieve the current page.
+        (WebCore::CaptionUserPreferences::setUserPrefersCaptions): Ditto.
+        (WebCore::CaptionUserPreferences::userPrefersSubtitles): Ditto.
+        (WebCore::CaptionUserPreferences::setUserPrefersSubtitles): Ditto.
+        (WebCore::CaptionUserPreferences::userPrefersTextDescriptions): Ditto.
+        (WebCore::CaptionUserPreferences::setUserPrefersTextDescriptions): Ditto.
+        * page/CaptionUserPreferences.h:
+
</ins><span class="cx"> 2016-09-16  Alex Christensen  &lt;achristensen@webkit.org&gt;
</span><span class="cx"> 
</span><span class="cx">         Use Vector&lt;LChar&gt; instead of StringBuilder for the ASCII parts of URLParser
</span></span></pre></div>
<a id="trunkSourceWebCorepageCaptionUserPreferencescpp"></a>
<div class="modfile"><h4>Modified: trunk/Source/WebCore/page/CaptionUserPreferences.cpp (206047 => 206048)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/WebCore/page/CaptionUserPreferences.cpp        2016-09-16 21:17:33 UTC (rev 206047)
+++ trunk/Source/WebCore/page/CaptionUserPreferences.cpp        2016-09-16 21:20:23 UTC (rev 206048)
</span><span class="lines">@@ -1,5 +1,5 @@
</span><span class="cx"> /*
</span><del>- * Copyright (C) 2013, 2015 Apple Inc. All rights reserved.
</del><ins>+ * Copyright (C) 2013-2016 Apple Inc. All rights reserved.
</ins><span class="cx">  *
</span><span class="cx">  * Redistribution and use in source and binary forms, with or without
</span><span class="cx">  * modification, are permitted provided that the following conditions
</span><span class="lines">@@ -49,8 +49,6 @@
</span><span class="cx">     : m_pageGroup(group)
</span><span class="cx">     , m_displayMode(ForcedOnly)
</span><span class="cx">     , m_timer(*this, &amp;CaptionUserPreferences::timerFired)
</span><del>-    , m_testingMode(false)
-    , m_havePreferences(false)
</del><span class="cx"> {
</span><span class="cx"> }
</span><span class="cx"> 
</span><span class="lines">@@ -99,9 +97,17 @@
</span><span class="cx">     notify();
</span><span class="cx"> }
</span><span class="cx"> 
</span><ins>+Page* CaptionUserPreferences::currentPage() const
+{
+    if (m_pageGroup.pages().isEmpty())
+        return nullptr;
+
+    return *(m_pageGroup.pages().begin());
+}
+
</ins><span class="cx"> bool CaptionUserPreferences::userPrefersCaptions() const
</span><span class="cx"> {
</span><del>-    Page* page = *(m_pageGroup.pages().begin());
</del><ins>+    Page* page = currentPage();
</ins><span class="cx">     if (!page)
</span><span class="cx">         return false;
</span><span class="cx"> 
</span><span class="lines">@@ -110,7 +116,7 @@
</span><span class="cx"> 
</span><span class="cx"> void CaptionUserPreferences::setUserPrefersCaptions(bool preference)
</span><span class="cx"> {
</span><del>-    Page* page = *(m_pageGroup.pages().begin());
</del><ins>+    Page* page = currentPage();
</ins><span class="cx">     if (!page)
</span><span class="cx">         return;
</span><span class="cx"> 
</span><span class="lines">@@ -120,7 +126,7 @@
</span><span class="cx"> 
</span><span class="cx"> bool CaptionUserPreferences::userPrefersSubtitles() const
</span><span class="cx"> {
</span><del>-    Page* page = *(pageGroup().pages().begin());
</del><ins>+    Page* page = currentPage();
</ins><span class="cx">     if (!page)
</span><span class="cx">         return false;
</span><span class="cx"> 
</span><span class="lines">@@ -129,7 +135,7 @@
</span><span class="cx"> 
</span><span class="cx"> void CaptionUserPreferences::setUserPrefersSubtitles(bool preference)
</span><span class="cx"> {
</span><del>-    Page* page = *(m_pageGroup.pages().begin());
</del><ins>+    Page* page = currentPage();
</ins><span class="cx">     if (!page)
</span><span class="cx">         return;
</span><span class="cx"> 
</span><span class="lines">@@ -139,7 +145,7 @@
</span><span class="cx"> 
</span><span class="cx"> bool CaptionUserPreferences::userPrefersTextDescriptions() const
</span><span class="cx"> {
</span><del>-    Page* page = *(m_pageGroup.pages().begin());
</del><ins>+    Page* page = currentPage();
</ins><span class="cx">     if (!page)
</span><span class="cx">         return false;
</span><span class="cx">     
</span><span class="lines">@@ -148,7 +154,7 @@
</span><span class="cx"> 
</span><span class="cx"> void CaptionUserPreferences::setUserPrefersTextDescriptions(bool preference)
</span><span class="cx"> {
</span><del>-    Page* page = *(m_pageGroup.pages().begin());
</del><ins>+    Page* page = currentPage();
</ins><span class="cx">     if (!page)
</span><span class="cx">         return;
</span><span class="cx">     
</span></span></pre></div>
<a id="trunkSourceWebCorepageCaptionUserPreferencesh"></a>
<div class="modfile"><h4>Modified: trunk/Source/WebCore/page/CaptionUserPreferences.h (206047 => 206048)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/WebCore/page/CaptionUserPreferences.h        2016-09-16 21:17:33 UTC (rev 206047)
+++ trunk/Source/WebCore/page/CaptionUserPreferences.h        2016-09-16 21:20:23 UTC (rev 206048)
</span><span class="lines">@@ -1,5 +1,5 @@
</span><span class="cx"> /*
</span><del>- * Copyright (C) 2012, 2013  Apple Inc. All rights reserved.
</del><ins>+ * Copyright (C) 2012-2016  Apple Inc. All rights reserved.
</ins><span class="cx">  *
</span><span class="cx">  * Redistribution and use in source and binary forms, with or without
</span><span class="cx">  * modification, are permitted provided that the following conditions
</span><span class="lines">@@ -23,8 +23,7 @@
</span><span class="cx">  * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 
</span><span class="cx">  */
</span><span class="cx"> 
</span><del>-#ifndef CaptionUserPreferences_h
-#define CaptionUserPreferences_h
</del><ins>+#pragma once
</ins><span class="cx"> 
</span><span class="cx"> #if ENABLE(VIDEO_TRACK)
</span><span class="cx"> 
</span><span class="lines">@@ -105,6 +104,7 @@
</span><span class="cx"> private:
</span><span class="cx">     void timerFired();
</span><span class="cx">     void notify();
</span><ins>+    Page* currentPage() const;
</ins><span class="cx"> 
</span><span class="cx">     PageGroup&amp; m_pageGroup;
</span><span class="cx">     mutable CaptionDisplayMode m_displayMode;
</span><span class="lines">@@ -114,11 +114,9 @@
</span><span class="cx">     String m_captionsStyleSheetOverride;
</span><span class="cx">     String m_primaryAudioTrackLanguageOverride;
</span><span class="cx">     unsigned m_blockNotificationsCounter { 0 };
</span><del>-    bool m_testingMode;
-    bool m_havePreferences;
</del><ins>+    bool m_testingMode { false };
+    bool m_havePreferences { false };
</ins><span class="cx"> };
</span><span class="cx">     
</span><span class="cx"> }
</span><span class="cx"> #endif
</span><del>-
-#endif
</del></span></pre>
</div>
</div>

</body>
</html>