Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 179f16e5d57b0911bb158de91e400e6809be04bf
      
https://github.com/WebKit/WebKit/commit/179f16e5d57b0911bb158de91e400e6809be04bf
  Author: Basuke Suzuki <[email protected]>
  Date:   2026-09-30 (Wed, 30 Sep 2026)

  Changed paths:
    A 
LayoutTests/navigation-api/navigation-intercept-handler-return-value-conversion-throws-crash-expected.txt
    A 
LayoutTests/navigation-api/navigation-intercept-handler-return-value-conversion-throws-crash.html
    M Source/WebCore/page/Navigation.cpp

  Log Message:
  -----------
  [Navigation API] Check for CallbackResultType::Success when collecting 
handler promises
https://bugs.webkit.org/show_bug.cgi?id=321712
rdar://185447313

Reviewed by Rupin Mittal and Charlie Wolfe.

A navigate event listener that calls event.intercept() terminates the 
WebContent process if
the handler's return value throws while being converted to a promise, for 
example a promise
with an own "constructor" getter that throws. The same applies to 
precommitHandler.

The generated code for these callbacks returns 
CallbackResultType::ExceptionThrown in that
case. Both handler loops in Navigation.cpp guarded the result with
`!= CallbackResultType::UnableToExecute`, so ExceptionThrown passed the check 
and
releaseReturnValue() was called on a result that carries an error, hitting
bad_expected_access. UnableToExecute can never be returned here anyway: both 
callbacks specify
SkipCallbackInvokeCheck, so the generated code does not emit the 
canInvokeCallback() check that
is the only producer of that value.

Check for Success instead, as every other consumer of a promise-returning 
callback in WebCore
already does (ViewTransition, WebLockManager, ReadableByteStreamController).

Test: 
navigation-api/navigation-intercept-handler-return-value-conversion-throws-crash.html

* 
LayoutTests/navigation-api/navigation-intercept-handler-return-value-conversion-throws-crash-expected.txt:
 Added.
* 
LayoutTests/navigation-api/navigation-intercept-handler-return-value-conversion-throws-crash.html:
 Added.
* Source/WebCore/page/Navigation.cpp:
(WebCore::Navigation::handleSameDocumentNavigation):
(WebCore::Navigation::runNavigatePrecommitHandlers):

Canonical link: https://commits.webkit.org/322283@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to