63d3d0
From b52cdd7a8525325deba04554d8a00a578c397d56 Mon Sep 17 00:00:00 2001
63d3d0
From: David Mitchell <davem@iabyn.com>
63d3d0
Date: Thu, 11 Jul 2019 15:17:48 +0100
63d3d0
Subject: [PATCH] threads::shared: fix leak
63d3d0
MIME-Version: 1.0
63d3d0
Content-Type: text/plain; charset=UTF-8
63d3d0
Content-Transfer-Encoding: 8bit
63d3d0
63d3d0
When assigning a shared reference value to a variable containing a
63d3d0
shared string, the PV buffer in the shared space was leaked. For
63d3d0
example:
63d3d0
63d3d0
    my $s :shared = "foo";
63d3d0
    my $t :shared  = shared_clone(\"bar");
63d3d0
    $s = $t; # "foo" in shared space leaked
63d3d0
63d3d0
This was showing up as failed smokes under ASan.
63d3d0
63d3d0
Petr Písař: Ported to 1.60 from perl commit
63d3d0
59c73bd3d62c5096a6f9b2e3cbe05e1ab4c158cf.
63d3d0
63d3d0
Signed-off-by: Petr Písař <ppisar@redhat.com>
63d3d0
---
63d3d0
 shared.xs | 15 +++++++++++----
63d3d0
 1 file changed, 11 insertions(+), 4 deletions(-)
63d3d0
63d3d0
diff --git a/shared.xs b/shared.xs
63d3d0
index 6cdf094..858c6d6 100644
63d3d0
--- a/shared.xs
63d3d0
+++ b/shared.xs
63d3d0
@@ -818,12 +818,19 @@ sharedsv_scalar_store(pTHX_ SV *sv, SV *ssv)
63d3d0
         SV *obj = SvRV(sv);
63d3d0
         SV *sobj = Perl_sharedsv_find(aTHX_ obj);
63d3d0
         if (sobj) {
63d3d0
+            SV* tmpref;
63d3d0
             SHARED_CONTEXT;
63d3d0
-            (void)SvUPGRADE(ssv, SVt_RV);
63d3d0
-            sv_setsv_nomg(ssv, &PL_sv_undef);
63d3d0
+            /* Creating a tmp ref to sobj then assigning it to ssv ensures
63d3d0
+             * that any previous contents of ssv are correctly freed
63d3d0
+             * by sv_setsv(). Not sure if there is a better, API-legal way
63d3d0
+             * to achieve this */
63d3d0
+            tmpref = newSV_type(SVt_RV);
63d3d0
+            SvRV_set(tmpref, sobj);
63d3d0
+            SvROK_on(tmpref);
63d3d0
+            SvREFCNT_inc_simple_NN(sobj);
63d3d0
+            sv_setsv_nomg(ssv, tmpref);
63d3d0
+            SvREFCNT_dec_NN(tmpref);
63d3d0
 
63d3d0
-            SvRV_set(ssv, SvREFCNT_inc(sobj));
63d3d0
-            SvROK_on(ssv);
63d3d0
             if (SvOBJECT(sobj)) {
63d3d0
                 /* Remove any old blessing */
63d3d0
                 SvREFCNT_dec(SvSTASH(sobj));
63d3d0
-- 
63d3d0
2.20.1
63d3d0