This is the mail archive of the libstdc++@gcc.gnu.org mailing list for the libstdc++ project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

[PATCH] PR libstdc++/81891 fix double-free in hashtable constructor


We introduced a regression in r214986 when changing the _Hashtable
range constructor to delegate to another constructor. That change
means that the object has completed construction after the target
constructor completes, and so if an exception is thrown in the
delegating constructor then the destructor will run. This results in
calling _M_deallocate_buckets twice, causing a double-free.

The fix is to simply omit the try-catch in the delegating constructor,
so that the destructor takes care of the clean up.

	PR libstdc++/81891
	* include/bits/hashtable.h (_Hashtable(_InputIterator, _InputIterator,
	size_type, const _H1&, const _H2&, const _Hash&, const _Equal&,
	const _ExtractKey&, const allocator_type&)): Let destructor do clean
	up if an exception is thrown.
	* testsuite/23_containers/unordered_map/cons/81891.cc: New.

Tested powerpc64le-linux, committed to trunk.

As a regression since 4.9 this needs to be backported to all active
branches.


Attachment: patch.txt
Description: Text document


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]