Skip to content

Commit c78f338

Browse files
Avoid crash in Chrome, issue 41487612 (#16893)
Fixes Chrome issue 41487612 Fixes Chrome crash introduced in NVDA pr #14647 Summary of the issue: Google has detected crashes in Chrome when users are running NVDA. Exact steps to reproduce are not known, but it is when an NVDA virtual buffer is destroyed. Could be on Chrome exit, NVDA exit, or closing a Chrome window. Chrome issue: issues.chromium.org/issues/41487612 It shows that a COM object tries to be released from an RPC worker thread by NVDA's in-process code, which causes Chrome to crash. NVDA pr #14647 introduced code to hold a reference to the document root accessible on the virtual buffer, so that NVDA could check if the document had died. However, it is this COM object that is automatically released when the virtual buffer id destroyed from an RPC worker thread. The COM object should really however be released when the virtual buffer is terminated in the correct UI thread, before destruction. Description of user facing changes No longer cause Google Chrome to crash when closing a document or exiting Chrome. Description of development approach VBufBackend_gecko_ia2::renderThread_terminate: correctly release the document root accessible. VBufBackend_gecko_ia2's destructor: in the very unlikely case where the VBufBackend_gecko_ia2::renderThread_terminate has not been called, detach the document root accessible, leaking it rather than inappropriately releasing it on the wrong thread.
1 parent 7227d51 commit c78f338

2 files changed

Lines changed: 19 additions & 0 deletions

File tree

‎nvdaHelper/vbufBackends/gecko_ia2/gecko_ia2.cpp‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1476,6 +1476,12 @@ void GeckoVBufBackend_t::renderThread_initialize() {
14761476
void GeckoVBufBackend_t::renderThread_terminate() {
14771477
unregisterWinEventHook(renderThread_winEventProcHook);
14781478
VBufBackend_t::renderThread_terminate();
1479+
// The backend holds a reference to the root accessible of the document.
1480+
// This must be specifically released here, in the UI thread where it was created.
1481+
// See https://issues.chromium.org/issues/41487612
1482+
if (this->rootDocAcc) {
1483+
this->rootDocAcc.Release();
1484+
}
14791485
}
14801486

14811487
void GeckoVBufBackend_t::render(VBufStorage_buffer_t* buffer, int docHandle, int ID, VBufStorage_controlFieldNode_t* oldNode) {
@@ -1502,6 +1508,18 @@ GeckoVBufBackend_t::GeckoVBufBackend_t(int docHandle, int ID): VBufBackend_t(doc
15021508
}
15031509

15041510
GeckoVBufBackend_t::~GeckoVBufBackend_t() {
1511+
// The backend holds a reference to the root accessible of the document.
1512+
// This must be specifically released in the UI thread where it was created.
1513+
// See https://issues.chromium.org/issues/41487612
1514+
// In most cases this will be released in renderThread_terminate.
1515+
// However in the unlikely case terminate can't run,
1516+
// we must detach and leak the COM pointer here.
1517+
// Otherwise it would be automatically deleted along with the backend which would cause a crash,
1518+
// as the COM object would be released from within an RPC worker thread.
1519+
nhAssert(!rootDocAcc);
1520+
if (this->rootDocAcc) {
1521+
this->rootDocAcc.Detach();
1522+
}
15051523
}
15061524

15071525
VBufBackend_t* GeckoVBufBackend_t_createInstance(int docHandle, int ID) {

‎user_docs/en/changes.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -71,6 +71,7 @@ A warning message will inform you if you try writing to a non-empty directory. (
7171
* NVDA will correctly announce radio and checkbox menu items when first entering sub-menus in Google Chrome and Mozilla Firefox. (#14550)
7272
* NVDA's browse mode find functionality is now more accurate when the page contains emojis. (#16317, @LeonarddeR)
7373
* In Mozilla Firefox, NVDA now correctly reports the current character, word and line when the cursor is at the insertion point at the end of a line. (#3156, @jcsteh)
74+
* No longer cause Google Chrome to crash when closing a document or exiting Chrome. (#16893)
7475
* NVDA will announce correctly the autocomplete suggestions in Eclipse and other Eclipse-based environments on Windows 11. (#16416, @thgcode)
7576
* Improved reliability of automatic text readout, particularly in terminal applications. (#15850, #16027, @Danstiv)
7677
* NVDA will correctly announce selection changes when editing a cell's text in Microsoft Excel. (#15843)

0 commit comments

Comments
 (0)