Skip to content

Digital Credentials: Fix safer C++ checker warnings in DigitalCredentialsCoordinator.cpp - #56614

Merged
webkit-commit-queue merged 1 commit into
WebKit:mainfrom
marcoscaceres:eng/Digital-Credentials-Fix-safer-C-checker-warnings-in-DigitalCredentials-DigitalCredentialsCoordinator-cpp
Jan 15, 2026
Merged

webkit-commit-queue merged 1 commit into
WebKit:mainfrom
marcoscaceres:eng/Digital-Credentials-Fix-safer-C-checker-warnings-in-DigitalCredentials-DigitalCredentialsCoordinator-cpp

Conversation

@marcoscaceres

@marcoscaceres marcoscaceres commented Jan 15, 2026 •

Copy link
Copy Markdown
Contributor

7a3c33b

Digital Credentials: Fix safer C++ checker warnings in DigitalCredentialsCoordinator.cpp
rdar://168196068
https://bugs.webkit.org/show_bug.cgi?id=305536

Reviewed by Anne van Kesteren.

Addressed safer C++ checker warnings in DigitalCredentialsCoordinator.cpp by ensuring
that any lambda capturing 'this' or members of 'this' uses a WeakPtr to avoid
dangling references if the coordinator is destroyed before the lambda is executed.

* Source/WebKit/WebProcess/DigitalCredentials/DigitalCredentialsCoordinator.cpp:
(WebKit::DigitalCredentialsCoordinator::showDigitalCredentialsPicker):

Canonical link: https://commits.webkit.org/305634@main

57f350f

Misc iOS, visionOS, tvOS & watchOS macOS Linux Windows Apple Internal
✅ 🧪 style ✅ 🛠 ios ✅ 🛠 mac ✅ 🛠 wpe   🛠 win ✅ 🛠 ios-apple
✅ 🛠 ios-sim ✅ 🛠 mac-AS-debug ✅ 🧪 wpe-wk2   🧪 win-tests ✅ 🛠 mac-apple
✅ 🧪 webkitperl ✅ 🧪 ios-wk2 ✅ 🧪 api-mac   🧪 api-wpe ✅ 🛠 vision-apple
✅ 🧪 ios-wk2-wpt ✅ 🧪 api-mac-debug ✅ 🛠 wpe-cairo-libwebrtc
✅ 🧪 api-ios ✅ 🛠 gtk
✅ 🛠 vision ✅ 🧪 mac-wk2 ❌ 🧪 gtk-wk2
✅ 🛠 vision-sim ✅ 🧪 mac-AS-debug-wk2 ✅ 🧪 api-gtk
✅ 🛠 🧪 merge ✅ 🧪 vision-wk2 ✅ 🧪 mac-wk2-stress ✅ 🛠 playstation
✅ 🛠 tv ✅ 🧪 mac-intel-wk2
✅ 🛠 tv-sim ✅ 🛠 mac-safer-cpp
✅ 🛠 watch
✅ 🛠 watch-sim

@marcoscaceres marcoscaceres self-assigned this Jan 15, 2026
@marcoscaceres
marcoscaceres requested a review from Copilot January 15, 2026 05:17

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses safer C++ checker warnings by protecting against use-after-free scenarios in the DigitalCredentialsCoordinator. The changes ensure that lambda captures do not create dangling references when the coordinator is destroyed before callback execution.

Changes:

  • Modified lambda capture to use WeakPtr instead of raw 'this' pointer
  • Added null check for WeakPtr before accessing coordinator members
  • Updated error codes to use AbortError for consistency

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@WebKit WebKit deleted a comment from Copilot AI Jan 15, 2026
@marcoscaceres
marcoscaceres requested a review from annevk January 15, 2026 05:19
@marcoscaceres marcoscaceres changed the title Digital Credentials: Fix safer C++ checker warnings in DigitalCredentials/DigitalCredentialsCoordinator.cpp Digital Credentials: Fix safer C++ checker warnings in DigitalCredentialsCoordinator.cpp Jan 15, 2026
@marcoscaceres
marcoscaceres force-pushed the eng/Digital-Credentials-Fix-safer-C-checker-warnings-in-DigitalCredentials-DigitalCredentialsCoordinator-cpp branch from aaf4d1f to c27e88d Compare January 15, 2026 05:30
@marcoscaceres
marcoscaceres marked this pull request as ready for review January 15, 2026 05:31
@webkit-ews-buildbot webkit-ews-buildbot added the merging-blocked Applied to prevent a change from being merged label Jan 15, 2026
Comment thread Source/WebKit/WebProcess/DigitalCredentials/DigitalCredentialsCoordinator.cpp Outdated
Comment thread Source/WebKit/WebProcess/DigitalCredentials/DigitalCredentialsCoordinator.cpp Outdated
@marcoscaceres marcoscaceres removed the merging-blocked Applied to prevent a change from being merged label Jan 15, 2026
@marcoscaceres
marcoscaceres force-pushed the eng/Digital-Credentials-Fix-safer-C-checker-warnings-in-DigitalCredentials-DigitalCredentialsCoordinator-cpp branch from c27e88d to 201ed84 Compare January 15, 2026 06:24

@annevk annevk left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good, but please make sure the Safer CPP bot runs to completion and you don't have to remove a file entry.

@marcoscaceres
marcoscaceres force-pushed the eng/Digital-Credentials-Fix-safer-C-checker-warnings-in-DigitalCredentials-DigitalCredentialsCoordinator-cpp branch from 201ed84 to 57f350f Compare January 15, 2026 08:33
@webkit-ews-buildbot webkit-ews-buildbot added the merging-blocked Applied to prevent a change from being merged label Jan 15, 2026
@marcoscaceres marcoscaceres added merge-queue Applied to send a pull request to merge-queue and removed merging-blocked Applied to prevent a change from being merged labels Jan 15, 2026
…ialsCoordinator.cpp

rdar://168196068
https://bugs.webkit.org/show_bug.cgi?id=305536

Reviewed by Anne van Kesteren.

Addressed safer C++ checker warnings in DigitalCredentialsCoordinator.cpp by ensuring
that any lambda capturing 'this' or members of 'this' uses a WeakPtr to avoid
dangling references if the coordinator is destroyed before the lambda is executed.

* Source/WebKit/WebProcess/DigitalCredentials/DigitalCredentialsCoordinator.cpp:
(WebKit::DigitalCredentialsCoordinator::showDigitalCredentialsPicker):

Canonical link: https://commits.webkit.org/305634@main
@webkit-commit-queue
webkit-commit-queue force-pushed the eng/Digital-Credentials-Fix-safer-C-checker-warnings-in-DigitalCredentials-DigitalCredentialsCoordinator-cpp branch from 57f350f to 7a3c33b Compare January 15, 2026 11:18
@webkit-commit-queue

Copy link
Copy Markdown
Collaborator

Committed 305634@main (7a3c33b): https://commits.webkit.org/305634@main

Reviewed commits have been landed. Closing PR #56614 and removing active labels.

@webkit-commit-queue
webkit-commit-queue merged commit 7a3c33b into WebKit:main Jan 15, 2026
@webkit-commit-queue webkit-commit-queue removed the merge-queue Applied to send a pull request to merge-queue label Jan 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants