#54524: fix: clear detached DevTools backlinks before widget destruction
Merged
Summary
Closing detached DevTools destroys the widget while InspectableWebContentsView still retains raw_ptr references to the widget-owned WebView and delegate.
Clear both non-owning pointers before resetting the widget. This avoids dangling raw_ptr references during detached DevTools teardown while preserving bounds saving and existing close/reopen behavior.
With raw_ptr checks enabled, the focused test reported the following diagnostic (unrelated stack frames omitted):
[DanglingPtr](1/3) A raw_ptr/raw_ref is dangling.
[DanglingPtr](2/3) First, the memory was freed at:
Stack trace:
...
#4 0x5f334be54d86 views::WebView::~WebView() [../../ui/views/controls/webview/webview.cc:96:21]
#5 0x5f33467d88e1 views::View::~View() [../../ui/views/view.cc:285:9]
#6 0x5f333b3e9b85 views::ClientView::~ClientView() [../../ui/views/window/client_view.h:34:28]
#7 0x5f333b3e94cb electron::DevToolsWindowDelegate::~DevToolsWindowDelegate() [../../electron/shell/browser/ui/inspectable_web_contents_view.cc:59:40]
#8 0x5f333b3e99c8 electron::DevToolsWindowDelegate::~DevToolsWindowDelegate() [../../electron/shell/browser/ui/inspectable_web_contents_view.cc:59:40]
#9 0x5f334680eaf4 views::WidgetDelegate::DeleteDelegate() [../../ui/views/widget/widget_delegate.cc:336:5]
...
#18 0x5f33467ff375 views::Widget::~Widget() [../../third_party/libc++/src/include/__memory/unique_ptr.h:74:5]
#19 0x5f334673f55e views::(anonymous namespace)::BubbleWidget::~BubbleWidget() [../../ui/views/bubble/bubble_dialog_delegate_view.cc:106:7]
#20 0x5f333b3e80d9 electron::InspectableWebContentsView::CloseDevTools() [../../third_party/libc++/src/include/__memory/unique_ptr.h:74:5]
#21 0x5f333b3de37e electron::InspectableWebContents::CloseDevTools() [../../electron/shell/browser/ui/inspectable_web_contents.cc:521:14]
...
[DanglingPtr](3/3) Later, the dangling raw_ptr was released at:
Stack trace:
...
#2 0x5f334317295d base::allocator::(anonymous namespace)::DanglingRawPtrReleased<>() [../../base/allocator/partition_alloc_support.cc:630:21]
#3 0x5f33431bb7c2 base::internal::RawPtrBackupRefImpl<>::ReleaseInternal() [../../base/allocator/partition_allocator/src/partition_alloc/in_slot_metadata.h:240:7]
#4 0x5f333b3e813a electron::InspectableWebContentsView::CloseDevTools() [../../base/allocator/partition_allocator/src/partition_alloc/pointers/raw_ptr_backup_ref_impl.h:194:7]
#5 0x5f333b3de37e electron::InspectableWebContents::CloseDevTools() [../../electron/shell/browser/ui/inspectable_web_contents.cc:521:14]
...
Validation
- Confirmed the dangling-pointer error before applying the fix, then rebuilt Electron and confirmed the same focused test passed without that error after the fix, with raw_ptr checks enabled in both runs:
disposes frames when a remote WebContents is destroyedinspec/api-web-contents.spec.ts. - All four selected DevTools tests passed, covering remote WebContents destruction, close/reopen, restoration of the undocked state, and setting a custom title.
- The instrumented post-fix run still logged separate, pre-existing
View/WebContentsViewwrapper dangling-pointer reports and allocator failures during worker shutdown; those are outside this fix. git diff --checkpassed.- Targeted C++ lint and clang-format checks passed for the changed file.
- Independent code review reported no findings.
Raw_ptr checks were enabled only for local validation; this PR does not change the raw_ptr build flags.
Notes: Fixed a potential crash when closing detached DevTools.
Backports
Semver Impact
Major
Breaking changes
Minor
New features
Patch
Bug fixes
None
Docs, tests, etc.
Semantic Versioning helps users understand the impact of updates:
- Major (X.y.z): Breaking changes that may require code modifications
- Minor (x.Y.z): New features that maintain backward compatibility
- Patch (x.y.Z): Bug fixes that don't change the API
- None: Changes that don't affect using facing parts of Electron