Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 8eb0e67119468277a7fa2076cea2afd3523d30d3
      
https://github.com/WebKit/WebKit/commit/8eb0e67119468277a7fa2076cea2afd3523d30d3
  Author: Chris Dumez <[email protected]>
  Date:   2026-09-29 (Tue, 29 Sep 2026)

  Changed paths:
    M Source/WebCore/platform/DragData.h
    M Source/WebCore/platform/cocoa/DragDataCocoa.mm
    M Source/WebKitLegacy/mac/WebView/WebView.mm

  Log Message:
  -----------
  REGRESSION(321892@main): Crash under 
WebDragClient::willPerformDragDestinationAction() in editing/pasteboard tests
https://bugs.webkit.org/show_bug.cgi?id=325567

Reviewed by Ryosuke Niwa.

On macOS, DragData stored its NSDraggingInfo as a raw pointer. When files
are dropped via file promises, -[WebView performDragOperation:] heap-allocates
a DragData and uses it in a lambda that runs asynchronously, after the
NSDraggingInfo may have been deallocated. 
WebDragClient::willPerformDragDestinationAction()
now calls protect() on DragData::platformData(), which crashes in objc_retain
on the dangling pointer.

Have DragData hold a RetainPtr to the NSDraggingInfo on macOS.

Also drop the temporary workaround that was added in WebView.mm by 322115@main.

* Source/WebCore/platform/DragData.h:
(WebCore::DragData::platformData const):
* Source/WebCore/platform/cocoa/DragDataCocoa.mm:
(WebCore::DragData::DragData):
* Source/WebKitLegacy/mac/WebView/WebView.mm:
(-[WebView performDragOperation:]):

Canonical link: https://commits.webkit.org/322208@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to