DescriptionMainFrameObserver is inline owned, so it shouldn't be freed by OnDestruct
MainFrameObserver is a RenderFrameObserver and as such is destroyed when
RenderFrame goes away. This happens as part of
RenderFrameObserver::OnDestruct. MainFrameObserver though is inline owned
by WebUIMojo and can be deleted before WebUIMojo is deleted. It results in
use-after-free when WebUIMojo is destructed and tries to free the already
freed MainFrameObserver.
This CL overrides OnDestruct, which allows the MainFrameObserver to stay
alive and be cleaned up by WebUIMojo.
BUG=357747
Committed: https://crrev.com/63b8975f954f2e10ee8c1b339c00b2b252f46132
Cr-Commit-Position: refs/heads/master@{#328990}
Patch Set 1 #
Total comments: 2
Patch Set 2 : Address comments by sky@. #
Messages
Total messages: 11 (3 generated)
|