Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(521)

Issue 2961573002: Fix nullptr deref in InvalidateKeyframeEffect (Closed)

Created:
3 years, 6 months ago by suzyh_UTC10 (ex-contributor)
Modified:
3 years, 5 months ago
CC:
darktears, blink-reviews, blink-reviews-animation_chromium.org, chromium-reviews, Eric Willigers, rjwright, shans
Target Ref:
refs/heads/master
Project:
chromium
Visibility:
Public.

Description

Fix nullptr deref in InvalidateKeyframeEffect Animation::InvalidateKeyframeEffect assumed that if it had content then it had a target element. After implementing the Animation constructor, it was possible to have created an Animation object with a KeyframeEffect with no target element. This patch checks whether the target is nullptr before dereferencing. BUG=734721 Review-Url: https://codereview.chromium.org/2961573002 Cr-Commit-Position: refs/heads/master@{#482558} Committed: https://chromium.googlesource.com/chromium/src/+/e4424b5ca106bdb36ad962a9daadb86131576e98

Patch Set 1 #

Total comments: 4

Patch Set 2 : Response to review #

Unified diffs Side-by-side diffs Delta from patch set Stats (+29 lines, -6 lines) Patch
A third_party/WebKit/LayoutTests/animations/keyframeeffect-no-target-crash.html View 1 1 chunk +16 lines, -0 lines 0 comments Download
A third_party/WebKit/LayoutTests/animations/keyframeeffect-no-target-crash-expected.txt View 1 chunk +1 line, -0 lines 0 comments Download
M third_party/WebKit/Source/core/animation/Animation.cpp View 1 1 chunk +12 lines, -6 lines 0 comments Download

Messages

Total messages: 14 (9 generated)
suzyh_UTC10 (ex-contributor)
3 years, 6 months ago (2017-06-26 01:58:30 UTC) #2
alancutter (OOO until 2018)
lgtm https://codereview.chromium.org/2961573002/diff/1/third_party/WebKit/LayoutTests/animations/keyframeeffect-no-target-crash.html File third_party/WebKit/LayoutTests/animations/keyframeeffect-no-target-crash.html (right): https://codereview.chromium.org/2961573002/diff/1/third_party/WebKit/LayoutTests/animations/keyframeeffect-no-target-crash.html#newcode3 third_party/WebKit/LayoutTests/animations/keyframeeffect-no-target-crash.html:3: let effect = new KeyframeEffect(null, null, { duration: ...
3 years, 6 months ago (2017-06-26 04:38:47 UTC) #7
suzyh_UTC10 (ex-contributor)
https://codereview.chromium.org/2961573002/diff/1/third_party/WebKit/LayoutTests/animations/keyframeeffect-no-target-crash.html File third_party/WebKit/LayoutTests/animations/keyframeeffect-no-target-crash.html (right): https://codereview.chromium.org/2961573002/diff/1/third_party/WebKit/LayoutTests/animations/keyframeeffect-no-target-crash.html#newcode3 third_party/WebKit/LayoutTests/animations/keyframeeffect-no-target-crash.html:3: let effect = new KeyframeEffect(null, null, { duration: 1000}); ...
3 years, 5 months ago (2017-06-27 05:12:15 UTC) #8
commit-bot: I haz the power
CQ is trying da patch. Follow status at: https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2961573002/20001
3 years, 5 months ago (2017-06-27 05:13:04 UTC) #11
commit-bot: I haz the power
3 years, 5 months ago (2017-06-27 07:06:36 UTC) #14
Message was sent while issue was closed.
Committed patchset #2 (id:20001) as
https://chromium.googlesource.com/chromium/src/+/e4424b5ca106bdb36ad962a9daad...

Powered by Google App Engine
This is Rietveld 408576698