74d8b422e5
- Fix double free crash during overload resolution (PR 12028, Sami Wagiaalla).
100 lines
2.9 KiB
Diff
100 lines
2.9 KiB
Diff
http://sourceware.org/ml/gdb-patches/2010-09/msg00321.html
|
|
Subject: [patch] PR 12028 "GDB crashes on a double free during overload resolution"
|
|
|
|
old_cleanups was being set twice making the later call to
|
|
discard_cleanups ignore the first 'make_cleanup' request.
|
|
|
|
The patch is proposed for both head and the 7.2 branch.
|
|
|
|
This has been regression tested on x8664 with gcc-4.4.4-10.fc13
|
|
|
|
|
|
Fix PR 12028: "GDB crashes on a double free during overload resolution "
|
|
|
|
2010-09-16 Sami Wagiaalla <swagiaal@redhat.com>
|
|
|
|
PR C++/12028
|
|
* valops.c (find_oload_champ_namespace_loop): removed incorrect
|
|
'old_cleanups' reassignment.
|
|
|
|
2010-09-16 Sami Wagiaalla <swagiaal@redhat.com>
|
|
|
|
* gdb.cp/pr12028.cc: New.
|
|
* gdb.cp/pr12028.exp: New.
|
|
|
|
diff --git a/gdb/testsuite/gdb.cp/pr12028.cc b/gdb/testsuite/gdb.cp/pr12028.cc
|
|
new file mode 100644
|
|
index 0000000..0fcab6b
|
|
--- /dev/null
|
|
+++ b/gdb/testsuite/gdb.cp/pr12028.cc
|
|
@@ -0,0 +1,21 @@
|
|
+class A{};
|
|
+class B{};
|
|
+class C: public B {};
|
|
+
|
|
+namespace D{
|
|
+ int foo (A) { return 11; }
|
|
+ int foo (C) { return 12; }
|
|
+}
|
|
+
|
|
+int main()
|
|
+{
|
|
+ A a;
|
|
+ B b;
|
|
+ C c;
|
|
+
|
|
+ D::foo (a);
|
|
+ // D::foo (b);
|
|
+ D::foo (c);
|
|
+
|
|
+ return 0;
|
|
+}
|
|
diff --git a/gdb/testsuite/gdb.cp/pr12028.exp b/gdb/testsuite/gdb.cp/pr12028.exp
|
|
new file mode 100644
|
|
index 0000000..746c6b5
|
|
--- /dev/null
|
|
+++ b/gdb/testsuite/gdb.cp/pr12028.exp
|
|
@@ -0,0 +1,29 @@
|
|
+# Copyright 2008 Free Software Foundation, Inc.
|
|
+
|
|
+# This program is free software; you can redistribute it and/or modify
|
|
+# it under the terms of the GNU General Public License as published by
|
|
+# the Free Software Foundation; either version 3 of the License, or
|
|
+# (at your option) any later version.
|
|
+#
|
|
+# This program is distributed in the hope that it will be useful,
|
|
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
+# GNU General Public License for more details.
|
|
+#
|
|
+# You should have received a copy of the GNU General Public License
|
|
+# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
+
|
|
+set testfile pr12028
|
|
+set srcfile ${testfile}.cc
|
|
+if { [prepare_for_testing ${testfile}.exp ${testfile} ${srcfile} {debug c++}] } {
|
|
+ return -1
|
|
+}
|
|
+
|
|
+############################################
|
|
+
|
|
+if ![runto_main] then {
|
|
+ perror "couldn't run to breakpoint main"
|
|
+ continue
|
|
+}
|
|
+
|
|
+gdb_test "p D::foo(b)" "Cannot resolve function foo to any overloaded instance"
|
|
diff --git a/gdb/valops.c b/gdb/valops.c
|
|
index 7fbad10..4e83a04 100644
|
|
--- a/gdb/valops.c
|
|
+++ b/gdb/valops.c
|
|
@@ -2715,7 +2715,7 @@ find_oload_champ_namespace_loop (struct type **arg_types, int nargs,
|
|
function symbol to start off with.) */
|
|
|
|
old_cleanups = make_cleanup (xfree, *oload_syms);
|
|
- old_cleanups = make_cleanup (xfree, *oload_champ_bv);
|
|
+ make_cleanup (xfree, *oload_champ_bv);
|
|
new_namespace = alloca (namespace_len + 1);
|
|
strncpy (new_namespace, qualified_name, namespace_len);
|
|
new_namespace[namespace_len] = '\0';
|