0
0
mirror of https://github.com/vim/vim.git synced 2025-07-26 11:04:33 -04:00

patch 9.0.0246: using freed memory when 'tagfunc' deletes the buffer

Problem:    Using freed memory when 'tagfunc' deletes the buffer.
Solution:   Make a copy of the tag name.
This commit is contained in:
Bram Moolenaar 2022-08-22 16:35:45 +01:00
parent 471c0fa3ee
commit adce965162
3 changed files with 22 additions and 1 deletions

View File

@ -281,6 +281,7 @@ do_tag(
char_u *buf_ffname = curbuf->b_ffname; // name to use for
// priority computation
int use_tfu = 1;
char_u *tofree = NULL;
// remember the matches for the last used tag
static int num_matches = 0;
@ -630,7 +631,12 @@ do_tag(
* When desired match not found yet, try to find it (and others).
*/
if (use_tagstack)
name = tagstack[tagstackidx].tagname;
{
// make a copy, the tagstack may change in 'tagfunc'
name = vim_strsave(tagstack[tagstackidx].tagname);
vim_free(tofree);
tofree = name;
}
#if defined(FEAT_QUICKFIX)
else if (g_do_tagpreview != 0)
name = ptag_entry.tagname;
@ -922,6 +928,7 @@ end_do_tag:
g_do_tagpreview = 0; // don't do tag preview next time
# endif
vim_free(tofree);
#ifdef FEAT_CSCOPE
return jumped_to_tag;
#else

View File

@ -389,4 +389,16 @@ func Test_tagfunc_callback()
%bw!
endfunc
func Test_tagfunc_wipes_buffer()
func g:Tag0unc0(t,f,o)
bwipe
endfunc
set tagfunc=g:Tag0unc0
new
cal assert_fails('tag 0', 'E987:')
delfunc g:Tag0unc0
set tagfunc=
endfunc
" vim: shiftwidth=2 sts=2 expandtab

View File

@ -731,6 +731,8 @@ static char *(features[]) =
static int included_patches[] =
{ /* Add new patch number below this line */
/**/
246,
/**/
245,
/**/