Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(143)

Issue 2031763003: Remove itself from the widget observers in destructor (Closed)

Created:
4 years, 6 months ago by yoshiki
Modified:
4 years, 5 months ago
CC:
chromium-reviews, Peter Beverloo, mlamouri+watch-notifications_chromium.org
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Remove itself from the widget observers in destructor This patch may fix the use-after-free reported in crbug.com/612050. BUG=612050 TEST=msan passes Committed: https://crrev.com/58f821b32a3b99bf15855225dff13d77f10d7484 Cr-Commit-Position: refs/heads/master@{#402408}

Patch Set 1 #

Total comments: 3

Patch Set 2 : for comment #17 #

Unified diffs Side-by-side diffs Delta from patch set Stats (+6 lines, -1 line) Patch
M ui/message_center/views/message_center_bubble.cc View 1 2 chunks +6 lines, -1 line 0 comments Download

Messages

Total messages: 25 (12 generated)
yoshiki
Oshima-san, do you think this patch is good?
4 years, 6 months ago (2016-06-16 13:03:29 UTC) #7
oshima
If this is deleted before widget, yes, but I'm not familiar with the destruction order ...
4 years, 6 months ago (2016-06-16 16:53:06 UTC) #9
msw
https://codereview.chromium.org/2031763003/diff/20001/ui/message_center/views/message_center_bubble.cc File ui/message_center/views/message_center_bubble.cc (right): https://codereview.chromium.org/2031763003/diff/20001/ui/message_center/views/message_center_bubble.cc#newcode71 ui/message_center/views/message_center_bubble.cc:71: bubble_view()->GetWidget()->RemoveObserver(this); Sorry, but TrayBubbleView is "specialized" (ie. not like ...
4 years, 6 months ago (2016-06-16 17:12:48 UTC) #10
yoshiki
skuhne@, could you check if this move is ok or not?
4 years, 6 months ago (2016-06-17 10:00:57 UTC) #12
Mr4D (OOO till 08-26)
Since Mukai is possibly not looking at this anymore I guess that xiyuan might know ...
4 years, 6 months ago (2016-06-17 23:10:08 UTC) #14
xiyuan
https://codereview.chromium.org/2031763003/diff/20001/ui/message_center/views/message_center_bubble.cc File ui/message_center/views/message_center_bubble.cc (right): https://codereview.chromium.org/2031763003/diff/20001/ui/message_center/views/message_center_bubble.cc#newcode71 ui/message_center/views/message_center_bubble.cc:71: bubble_view()->GetWidget()->RemoveObserver(this); It probably would crash since MessageCenterBubble has a ...
4 years, 6 months ago (2016-06-20 16:04:40 UTC) #15
yoshiki
On 2016/06/20 16:04:40, xiyuan wrote: > https://codereview.chromium.org/2031763003/diff/20001/ui/message_center/views/message_center_bubble.cc > File ui/message_center/views/message_center_bubble.cc (right): > > https://codereview.chromium.org/2031763003/diff/20001/ui/message_center/views/message_center_bubble.cc#newcode71 > ...
4 years, 6 months ago (2016-06-20 18:04:55 UTC) #16
xiyuan
On 2016/06/20 18:04:55, yoshiki wrote: > If I add the null-check for the bubble view ...
4 years, 6 months ago (2016-06-20 20:37:08 UTC) #17
yoshiki
On 2016/06/20 20:37:08, xiyuan wrote: > On 2016/06/20 18:04:55, yoshiki wrote: > > If I ...
4 years, 5 months ago (2016-06-28 04:32:36 UTC) #18
xiyuan
lgtm
4 years, 5 months ago (2016-06-28 04:59:47 UTC) #19
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2031763003/40001
4 years, 5 months ago (2016-06-28 05:02:37 UTC) #21
commit-bot: I haz the power
Committed patchset #2 (id:40001)
4 years, 5 months ago (2016-06-28 05:29:12 UTC) #23
commit-bot: I haz the power
4 years, 5 months ago (2016-06-28 05:30:29 UTC) #25
Message was sent while issue was closed.
Patchset 2 (id:??) landed as
https://crrev.com/58f821b32a3b99bf15855225dff13d77f10d7484
Cr-Commit-Position: refs/heads/master@{#402408}

Powered by Google App Engine
This is Rietveld 408576698