Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: 179f16e5d57b0911bb158de91e400e6809be04bf
https://github.com/WebKit/WebKit/commit/179f16e5d57b0911bb158de91e400e6809be04bf
Author: Basuke Suzuki <[email protected]>
Date: 2026-09-30 (Wed, 30 Sep 2026)
Changed paths:
A
LayoutTests/navigation-api/navigation-intercept-handler-return-value-conversion-throws-crash-expected.txt
A
LayoutTests/navigation-api/navigation-intercept-handler-return-value-conversion-throws-crash.html
M Source/WebCore/page/Navigation.cpp
Log Message:
-----------
[Navigation API] Check for CallbackResultType::Success when collecting
handler promises
https://bugs.webkit.org/show_bug.cgi?id=321712
rdar://185447313
Reviewed by Rupin Mittal and Charlie Wolfe.
A navigate event listener that calls event.intercept() terminates the
WebContent process if
the handler's return value throws while being converted to a promise, for
example a promise
with an own "constructor" getter that throws. The same applies to
precommitHandler.
The generated code for these callbacks returns
CallbackResultType::ExceptionThrown in that
case. Both handler loops in Navigation.cpp guarded the result with
`!= CallbackResultType::UnableToExecute`, so ExceptionThrown passed the check
and
releaseReturnValue() was called on a result that carries an error, hitting
bad_expected_access. UnableToExecute can never be returned here anyway: both
callbacks specify
SkipCallbackInvokeCheck, so the generated code does not emit the
canInvokeCallback() check that
is the only producer of that value.
Check for Success instead, as every other consumer of a promise-returning
callback in WebCore
already does (ViewTransition, WebLockManager, ReadableByteStreamController).
Test:
navigation-api/navigation-intercept-handler-return-value-conversion-throws-crash.html
*
LayoutTests/navigation-api/navigation-intercept-handler-return-value-conversion-throws-crash-expected.txt:
Added.
*
LayoutTests/navigation-api/navigation-intercept-handler-return-value-conversion-throws-crash.html:
Added.
* Source/WebCore/page/Navigation.cpp:
(WebCore::Navigation::handleSameDocumentNavigation):
(WebCore::Navigation::runNavigatePrecommitHandlers):
Canonical link: https://commits.webkit.org/322283@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications