Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: 8eb0e67119468277a7fa2076cea2afd3523d30d3
https://github.com/WebKit/WebKit/commit/8eb0e67119468277a7fa2076cea2afd3523d30d3
Author: Chris Dumez <[email protected]>
Date: 2026-09-29 (Tue, 29 Sep 2026)
Changed paths:
M Source/WebCore/platform/DragData.h
M Source/WebCore/platform/cocoa/DragDataCocoa.mm
M Source/WebKitLegacy/mac/WebView/WebView.mm
Log Message:
-----------
REGRESSION(321892@main): Crash under
WebDragClient::willPerformDragDestinationAction() in editing/pasteboard tests
https://bugs.webkit.org/show_bug.cgi?id=325567
Reviewed by Ryosuke Niwa.
On macOS, DragData stored its NSDraggingInfo as a raw pointer. When files
are dropped via file promises, -[WebView performDragOperation:] heap-allocates
a DragData and uses it in a lambda that runs asynchronously, after the
NSDraggingInfo may have been deallocated.
WebDragClient::willPerformDragDestinationAction()
now calls protect() on DragData::platformData(), which crashes in objc_retain
on the dangling pointer.
Have DragData hold a RetainPtr to the NSDraggingInfo on macOS.
Also drop the temporary workaround that was added in WebView.mm by 322115@main.
* Source/WebCore/platform/DragData.h:
(WebCore::DragData::platformData const):
* Source/WebCore/platform/cocoa/DragDataCocoa.mm:
(WebCore::DragData::DragData):
* Source/WebKitLegacy/mac/WebView/WebView.mm:
(-[WebView performDragOperation:]):
Canonical link: https://commits.webkit.org/322208@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications