Bug 1315885 - Part 3: Transfer the ownership of ReactionQueue's entry due to re-enter CustomElementReactionsStack::InvokeReactions.

Tag UXP Issue #1344
This commit is contained in:
Gaming4JC 2020-01-04 22:05:07 -05:00 • committed by Roy Tam
commit 931b14f847

View file

@ -974,6 +974,7 @@ CustomElementReactionsStack::InvokeBackupQueue()
void void
CustomElementReactionsStack::InvokeReactions(ElementQueue& aElementQueue) CustomElementReactionsStack::InvokeReactions(ElementQueue& aElementQueue)
{ {
// Note: It's possible to re-enter this method.
for (uint32_t i = 0; i < aElementQueue.Length(); ++i) { for (uint32_t i = 0; i < aElementQueue.Length(); ++i) {
nsCOMPtr<Element> element = do_QueryReferent(aElementQueue[i]); nsCOMPtr<Element> element = do_QueryReferent(aElementQueue[i]);
@ -984,10 +985,14 @@ CustomElementReactionsStack::InvokeReactions(ElementQueue& aElementQueue)
RefPtr<CustomElementData> elementData = element->GetCustomElementData(); RefPtr<CustomElementData> elementData = element->GetCustomElementData();
MOZ_ASSERT(elementData, "CustomElementData should exist"); MOZ_ASSERT(elementData, "CustomElementData should exist");
nsTArray<nsAutoPtr<CustomElementReaction>>& reactions = auto& reactions = elementData->mReactionQueue;
elementData->mReactionQueue;
for (uint32_t j = 0; j < reactions.Length(); ++j) { for (uint32_t j = 0; j < reactions.Length(); ++j) {
reactions.ElementAt(j)->Invoke(element); // Transfer the ownership of the entry due to reentrant invocation of
// this funciton. The entry will be removed when bug 1379573 is landed.
auto reaction(Move(reactions.ElementAt(j)));
if (reaction) {
reaction->Invoke(element);
}
} }
reactions.Clear(); reactions.Clear();
} }