Chromium Code Reviews
DescriptionFix heap-use-after-free in cc::SurfaceManager::Destroy
There is no need to call DestroyAll() on surface_factory_ inside
OffscreenCanvasSurfaceImpl's destructor, because surface_factory_ is its unique
pointer and SurfaceFactory's own destructor already contains DestroyAll().
TBR=piman@chromium.org
BUG=621849
Committed: https://crrev.com/cfe3e0ebde0e9448cb5964373a6938afe229f397
Cr-Commit-Position: refs/heads/master@{#400994}
Patch Set 1 #
Messages
Total messages: 11 (5 generated)
|
|||||||||||||||||||