[Webkit-unassigned] [Bug 144903] [GTK] Crash at WebCore::FrameView::removeChild()

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Tue May 12 11:38:24 PDT 2015


https://bugs.webkit.org/show_bug.cgi?id=144903

--- Comment #2 from Zan Dobersek <zan at falconsigh.net> ---
(In reply to comment #1)
> WebCore::FrameView::removeChild (this=0x7f74a412cc00, widget=0x0)
> 
> This can't happen in trunk, since it now receives a reference, not a
> pointer. And the same in 2.8, so I guess this is a blocker only for wk1.

It can happen, but one would have to try a bit harder to dereference a null pointer into the removeChild() call.

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.webkit.org/pipermail/webkit-unassigned/attachments/20150512/0f46a830/attachment.html>


More information about the webkit-unassigned mailing list