prevent use-after-free bugs in cased objects the bug happens specifically when deleting an item in a seq. The item taking it's place might not have the same case fields. Then =sink(x[i], move x[xl]) might leave the deleted fields still in memory! If the new item switches branches again, you get a use-after-free bug.
This commit is contained in:
parent
cde6b2aab8
commit
8dcf367e52
1 changed files with 3 additions and 0 deletions
|
|
@ -165,9 +165,12 @@ proc fillBodyObj(c: var TLiftCtx; n, body, x, y: PNode; enforceDefaultOp: bool)
|
||||||
# the value needs to be destroyed before we assign the selector
|
# the value needs to be destroyed before we assign the selector
|
||||||
# or the value is lost
|
# or the value is lost
|
||||||
let prevKind = c.kind
|
let prevKind = c.kind
|
||||||
|
let prevAddMemReset = c.addMemReset
|
||||||
c.kind = attachedDestructor
|
c.kind = attachedDestructor
|
||||||
|
c.addMemReset = true
|
||||||
fillBodyObj(c, n, body, x, y, enforceDefaultOp = false)
|
fillBodyObj(c, n, body, x, y, enforceDefaultOp = false)
|
||||||
c.kind = prevKind
|
c.kind = prevKind
|
||||||
|
c.addMemReset = prevAddMemReset
|
||||||
localEnforceDefaultOp = true
|
localEnforceDefaultOp = true
|
||||||
|
|
||||||
if c.kind != attachedDestructor:
|
if c.kind != attachedDestructor:
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue