Mercurial > vim
diff src/userfunc.c @ 16969:8c794a694d66 v8.1.1485
patch 8.1.1485: double free when garbage_collect() is used in autocommand
commit https://github.com/vim/vim/commit/c07f67ad0e9c48a07d49f2d67eb63e183a22386a
Author: Bram Moolenaar <Bram@vim.org>
Date: Thu Jun 6 19:03:17 2019 +0200
patch 8.1.1485: double free when garbage_collect() is used in autocommand
Problem: Double free when garbage_collect() is used in autocommand.
Solution: Have garbage collection also set the copyID in funccal_stack.
author | Bram Moolenaar <Bram@vim.org> |
---|---|
date | Thu, 06 Jun 2019 19:15:06 +0200 |
parents | a836d122231a |
children | d244a9be99db |
line wrap: on
line diff
--- a/src/userfunc.c +++ b/src/userfunc.c @@ -4030,11 +4030,18 @@ set_ref_in_funccal(funccall_T *fc, int c int set_ref_in_call_stack(int copyID) { - int abort = FALSE; - funccall_T *fc; + int abort = FALSE; + funccall_T *fc; + funccal_entry_T *entry; for (fc = current_funccal; fc != NULL; fc = fc->caller) abort = abort || set_ref_in_funccal(fc, copyID); + + // Also go through the funccal_stack. + for (entry = funccal_stack; entry != NULL; entry = entry->next) + for (fc = entry->top_funccal; fc != NULL; fc = fc->caller) + abort = abort || set_ref_in_funccal(fc, copyID); + return abort; }