Commit 461bc3b
authored
Stop managed_array from accidentally changing C++ types (#155)
Storing non-POD types in char buffers is unsafe.
* Ensure alignments are compatible with desired type.
* Ensure raw data is copied with `memcpy`
Otherwise, `_list_handouts` placement-constructs entries as one type
(`list_impl`) which is changed when they're copied by the copy
constructor of T (`list_interface`, different type). For POD data this
wouldn't matter, but here it changes the vtable pointer and indirectly
causes an OOB write.
This crashed my memory allocator, which is how I spotted it.1 parent 645f5a6 commit 461bc3b
2 files changed
Lines changed: 17 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
| 38 | + | |
38 | 39 | | |
39 | 40 | | |
40 | 41 | | |
| |||
113 | 114 | | |
114 | 115 | | |
115 | 116 | | |
| 117 | + | |
116 | 118 | | |
117 | 119 | | |
118 | 120 | | |
| |||
197 | 199 | | |
198 | 200 | | |
199 | 201 | | |
200 | | - | |
201 | | - | |
| 202 | + | |
| 203 | + | |
202 | 204 | | |
203 | 205 | | |
204 | 206 | | |
| |||
273 | 275 | | |
274 | 276 | | |
275 | 277 | | |
| 278 | + | |
| 279 | + | |
276 | 280 | | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
277 | 287 | | |
| 288 | + | |
278 | 289 | | |
279 | | - | |
280 | 290 | | |
281 | | - | |
282 | | - | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
283 | 294 | | |
284 | 295 | | |
285 | 296 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
825 | 825 | | |
826 | 826 | | |
827 | 827 | | |
| 828 | + | |
828 | 829 | | |
829 | 830 | | |
830 | 831 | | |
| |||
0 commit comments