From f6bf1d7b30078adf4fb26a89f3b5988954c3287c Mon Sep 17 00:00:00 2001 From: Paul Miller Date: Fri, 19 Dec 2014 17:51:18 -0800 Subject: [PATCH] Fix crash on pasting text in a WebView WindowDecorActionBar and Chrome's ContentViewCore each have their own ActionMode reference. ActionModeImpl.finish() nulls WindowDecorActionBar's reference and calls mCallback.onDestroyActionMode() to null ContentViewCore's reference. But if the callback is deferred, there is a period when the ActionMode is finished (and mCallback is null), but ContentViewCore doesn't know. ContentViewCore may try to invalidate() the ActionMode, which will crash on the null mCallback. Make ActionModeImpl more permissive so that calling invalidate() during this period does nothing. BUG:18758329 Change-Id: I407fa0e0cd3cffa217e165caed83130d44760316 --- .../com/android/internal/app/WindowDecorActionBar.java | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/core/java/com/android/internal/app/WindowDecorActionBar.java b/core/java/com/android/internal/app/WindowDecorActionBar.java index d95f0e591e0e2..061b535e220db 100644 --- a/core/java/com/android/internal/app/WindowDecorActionBar.java +++ b/core/java/com/android/internal/app/WindowDecorActionBar.java @@ -993,6 +993,13 @@ public class WindowDecorActionBar extends ActionBar implements @Override public void invalidate() { + if (mActionMode != this) { + // Not the active action mode - no-op. It's possible we are + // currently deferring onDestroy, so the app doesn't yet know we + // are going away and is trying to use us. That's also a no-op. + return; + } + mMenu.stopDispatchingItemsChanged(); try { mCallback.onPrepareActionMode(this, mMenu);