Issue metadata
Sign in to add a comment
|
Possible crash after r403093 |
||||||||||||||||||||||
Issue descriptionThe code in https://chromium.googlesource.com/chromium/src/+/ef9c38f033c0f5b11defe2210d2d00737c41b76e + index = m_listItems.find(&subject); + DCHECK_NE(index, WTF::kNotFound); + } + m_listItems.remove(index); This might cause release crash in mlistItems.remove().
,
Jul 1 2016
,
Jul 1 2016
,
Jul 1 2016
Your change meets the bar and is auto-approved for M53 (branch: 2785)
,
Jul 1 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/3fe2c3902b205e99caff0e774a1b4d19c019276d commit 3fe2c3902b205e99caff0e774a1b4d19c019276d Author: Kent Tamura <tkent@chromium.org> Date: Fri Jul 01 22:30:55 2016 Merge "Update a comment and fix a possible crash in HTMLSelectElement::setRecalcListItems." to M53. This is a follow-up of crrev.com/403093. - Replace a TODO comment with an explanation, and add a test to reproduce the scenario. - Fix a possible crash by m_listItems.remove(WTF::kNotFound) just in case. We don't find a reproduction. BUG= 625050 ,625091 Review-Url: https://codereview.chromium.org/2103663006 Cr-Commit-Position: refs/heads/master@{#403416} (cherry picked from commit 760c56deb503e184f25a77782e743b6d46732cb6) Review URL: https://codereview.chromium.org/2118973003 . Cr-Commit-Position: refs/branch-heads/2785@{#3} Cr-Branched-From: 68623971be0cfc492a2cb0427d7f478e7b214c24-refs/heads/master@{#403382} [modify] https://crrev.com/3fe2c3902b205e99caff0e774a1b4d19c019276d/third_party/WebKit/Source/core/html/HTMLSelectElement.cpp [modify] https://crrev.com/3fe2c3902b205e99caff0e774a1b4d19c019276d/third_party/WebKit/Source/core/html/HTMLSelectElementTest.cpp
,
Jul 3 2016
Issue 625091 has been merged into this issue.
,
Jul 7 2016
Tested the issue on Win 7,Mac 10.11.5 and Ubuntu 14.04 using 53.0.2785.8 referring to the comment www. crbug.com/623891#c2 , and https://output.jsbin.com/fojaza. The page shows unresponsive message while tried to delete 500000 and after clicked once or twice on "wait" option it deletes the options.If clicked on "Kill" the Aw,Snap! page is seen. tkent@: Could you please review the attached screen shot and update if its fine.
,
Jul 7 2016
#7, it's unrelated to this bug, and it's an expected behavior.
,
Jul 8 2016
Thanks for the update, Adding the respective TE-Verified labels for the same. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by bugdroid1@chromium.org
, Jul 1 2016