LibWeb: Disentangle both ends of a MessagePort at once

Otherwise, the remote end believes it is still entangled and may try to
access its own (now null) remote port. This fixes a crash in WPT.
This commit is contained in:
Timothy Flynn 2025-05-23 15:16:23 -04:00 committed by Shannon Booth
parent ea44a1c2c7
commit fbd1f77161
2 changed files with 17 additions and 1 deletions

View file

@ -147,9 +147,13 @@ WebIDL::ExceptionOr<void> MessagePort::transfer_receiving_steps(HTML::TransferDa
void MessagePort::disentangle()
{
if (m_remote_port) {
if (auto remote_port = m_remote_port) {
// Set the pointers to null before disentangling the remote port to prevent infinite recursion here.
m_remote_port->m_remote_port = nullptr;
m_remote_port = nullptr;
if (remote_port)
remote_port->disentangle();
}
if (m_transport) {

View file

@ -0,0 +1,12 @@
<!DOCTYPE html>
<script type="module">
let a = new ReadableStream();
let b = self.open()
let f = new b.WritableStream();
a.pipeThrough(
{ "readable": a, "writable": f },
{ "signal": AbortSignal.abort() }
)
await new Promise(setTimeout);
structuredClone(undefined, { "transfer": [f] })
</script>