Prevent use-after-free bugs in object variants. Fixes bug #20305 (#20300) [backport]

prevent use-after-free bugs in cased objects

the bug happens specifically when deleting
an item in a seq. The item taking it's place
might not have the same case fields. Then =sink(x[i], move x[xl])
might leave the deleted fields still in memory!
If the new item switches branches again, you get a use-after-free bug.
This commit is contained in:
Antonis Geralis 2022-09-05 09:26:02 +03:00 • committed by GitHub
commit 8dcf367e52
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -165,9 +165,12 @@ proc fillBodyObj(c: var TLiftCtx; n, body, x, y: PNode; enforceDefaultOp: bool)
# the value needs to be destroyed before we assign the selector # the value needs to be destroyed before we assign the selector
# or the value is lost # or the value is lost
let prevKind = c.kind let prevKind = c.kind
let prevAddMemReset = c.addMemReset
c.kind = attachedDestructor c.kind = attachedDestructor
c.addMemReset = true
fillBodyObj(c, n, body, x, y, enforceDefaultOp = false) fillBodyObj(c, n, body, x, y, enforceDefaultOp = false)
c.kind = prevKind c.kind = prevKind
c.addMemReset = prevAddMemReset
localEnforceDefaultOp = true localEnforceDefaultOp = true
if c.kind != attachedDestructor: if c.kind != attachedDestructor: