Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(2998)

Unified Diff: content/renderer/render_frame_proxy.cc

Issue 2410153005: Fix RenderView reuse issues when canceling a pending RenderFrameHost. (Closed)
Patch Set: Nits Created 4 years, 2 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: content/renderer/render_frame_proxy.cc
diff --git a/content/renderer/render_frame_proxy.cc b/content/renderer/render_frame_proxy.cc
index 4053b914200a1598e5ec712d4771dc28c49dc35f..1a833e2fa27d79c0e61392ab96ff95da1947789c 100644
--- a/content/renderer/render_frame_proxy.cc
+++ b/content/renderer/render_frame_proxy.cc
@@ -111,6 +111,14 @@ RenderFrameProxy* RenderFrameProxy::CreateFrameProxy(
proxy.get(), opener);
render_view->webview()->setMainFrame(web_frame);
render_widget = render_view->GetWidget();
+
+ // If the RenderView is reused by this proxy after having been used for a
+ // pending RenderFrame that was discarded, its swapped out state needs to
+ // be updated, as the OnSwapOut flow which normally does this won't happen
+ // in that case. See https://crbug.com/653746 and
+ // https://crbug.com/651980.
+ if (!render_view->is_swapped_out())
+ render_view->SetSwappedOut(true);
} else {
// Create a frame under an existing parent. The parent is always expected
// to be a RenderFrameProxy, because navigations initiated by local frames

Powered by Google App Engine
This is Rietveld 408576698