New issue
Advanced search Search tips

Issue 899089 link

Starred by 1 user

Issue metadata

Status: Available
Owner: ----
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Oilpan plugin doesn't seem to warn about global raw pointers to GC objects

Project Member Reported by dcheng@chromium.org, Oct 25

Issue description

A previous iteration of https://chromium-review.googlesource.com/c/chromium/src/+/1299537 landed and was reverted for causing crashes.

The crashes are likely because a global variable of type LocalFrame* was added; since it's not a Persistent/WeakPersistent, Oilpan doesn't know about it. If the LocalFrame object is swept, then we have a UaF.
 

Comment 1 by mlippautz@chromium.org, Jan 16 (6 days ago)

Labels: -Pri-1 Pri-3
All correct. I don't think this is P1 though.

Sign in to add a comment