[Webkit-unassigned] [Bug 18585] Frame::ownerRenderer() is likely causing strange crashes

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Fri Apr 18 10:44:38 PDT 2008


------- Comment #4 from eric at webkit.org  2008-04-18 10:44 PDT -------
I think this is caused by <object> elements not disassociating themselves with
the frames that they created when they decide to render fallback content (or
any other content).  I imagine if you were to change an <object> from pointing
at an .html file to pointing at a .png, it might crash in a similar manner.

It looks like there are only a few clients of ownerRenderer():

WebCore/page/FrameView.cpp:        RenderPart* renderer =
WebCore/page/FrameView.cpp:        if (RenderPart* renderer =
WebKit/gtk/WebCoreSupport/FrameLoaderClientGtk.cpp:    if
WebKit/mac/WebView/WebFrameView.mm:    if (RenderPart* owner =
frame->ownerRenderer()) {
WebKit/qt/WebCoreSupport/FrameLoaderClientQt.cpp:    if
WebKit/win/WebCoreSupport/WebFrameLoaderClient.cpp:    if

It looks safe to return 0 from ownerRenderer() so I'm going to fix this
potential crash by doing so.  I'm not sure it's right for HTMLObjectElements to
remain the ownerElement for these canceled/errored frames so long... but I
guess we can deal with that later.

Configure bugmail: http://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.

More information about the webkit-unassigned mailing list