]> git.ipfire.org Git - thirdparty/vim.git/commitdiff
patch 9.0.1865: Vim9: garbage collection may cause crash v9.0.1865
authorYegappan Lakshmanan <yegappan@yahoo.com>
Mon, 4 Sep 2023 20:14:28 +0000 (22:14 +0200)
committerChristian Brabandt <cb@256bit.org>
Mon, 4 Sep 2023 20:14:28 +0000 (22:14 +0200)
Problem:  Vim9: garbage collection may cause crash
Solution: validate that class members typeval is not null

closes: #13028

Signed-off-by: Christian Brabandt <cb@256bit.org>
Co-authored-by: Yegappan Lakshmanan <yegappan@yahoo.com>
src/eval.c
src/testdir/test_vim9_class.vim
src/version.c

index 4143dd2ac681183e120a34177a6e0fbb022b9c39..7cfe68cc66bfb4f3fd7ca68147e8cc6425dad3de 100644 (file)
@@ -5725,10 +5725,15 @@ set_ref_in_item_class(
        return FALSE;
 
     cl->class_copyID = copyID;
-    for (int i = 0; !abort && i < cl->class_class_member_count; ++i)
-       abort = abort || set_ref_in_item(
-               &cl->class_members_tv[i],
-               copyID, ht_stack, list_stack);
+    if (cl->class_members_tv != NULL)
+    {
+       // The "class_members_tv" table is allocated only for regular classes
+       // and not for interfaces.
+       for (int i = 0; !abort && i < cl->class_class_member_count; ++i)
+           abort = abort || set_ref_in_item(
+                   &cl->class_members_tv[i],
+                   copyID, ht_stack, list_stack);
+    }
 
     for (int i = 0; !abort && i < cl->class_class_function_count; ++i)
        abort = abort || set_ref_in_func(NULL,
index 72cdaf086cf75acc167ae3c006d32ba6506d160d..8ae136f283f50e6382210846d79feb75c55bee83 100644 (file)
@@ -1307,6 +1307,60 @@ func Test_class_garbagecollect()
   call v9.CheckScriptSuccess(lines)
 endfunc
 
+" Test interface garbage collection
+func Test_interface_garbagecollect()
+  let lines =<< trim END
+    vim9script
+
+    interface I
+      static ro_class_var: number
+      public static rw_class_var: number
+      static _priv_class_var: number
+      this.ro_obj_var: number
+      public this.rw_obj_var: number
+      this._priv_obj_var: number
+
+      static def ClassFoo(): number
+      static def _ClassBar(): number
+      def ObjFoo(): number
+      def _ObjBar(): number
+    endinterface
+
+    class A implements I
+      static ro_class_var: number = 10
+      public static rw_class_var: number = 20
+      static _priv_class_var: number = 30
+      this.ro_obj_var: number = 40
+      public this.rw_obj_var: number = 50
+      this._priv_obj_var: number = 60
+
+      static def _ClassBar(): number
+        return _priv_class_var
+      enddef
+
+      static def ClassFoo(): number
+        return ro_class_var + rw_class_var + A._ClassBar()
+      enddef
+
+      def _ObjBar(): number
+        return this._priv_obj_var
+      enddef
+
+      def ObjFoo(): number
+        return this.ro_obj_var + this.rw_obj_var + this._ObjBar()
+      enddef
+    endclass
+
+    assert_equal(60, A.ClassFoo())
+    var o = A.new()
+    assert_equal(150, o.ObjFoo())
+    test_garbagecollect_now()
+    assert_equal(60, A.ClassFoo())
+    assert_equal(150, o.ObjFoo())
+  END
+  call v9.CheckScriptSuccess(lines)
+endfunc
+
 def Test_class_function()
   var lines =<< trim END
       vim9script
index c2faee46cc57cc6e34fe677d8168f8d708b4c528..c4b793f5069d11e44f1b5aced98415d486eaa995 100644 (file)
@@ -699,6 +699,8 @@ static char *(features[]) =
 
 static int included_patches[] =
 {   /* Add new patch number below this line */
+/**/
+    1865,
 /**/
     1864,
 /**/