Blame SOURCES/0017-QQmlJs-FixedPoolArray-fix-UB-precondition-violation-.patch
|
|
03bb49 |
From c6e595e7fbbe80c8db7ae33d8af05a4fd946a2f5 Mon Sep 17 00:00:00 2001
|
|
|
03bb49 |
From: Marc Mutz <marc.mutz@qt.io>
|
|
|
03bb49 |
Date: Tue, 21 Dec 2021 09:20:17 +0100
|
|
|
03bb49 |
Subject: [PATCH 17/20] QQmlJs::FixedPoolArray: fix UB (precondition violation)
|
|
|
03bb49 |
in allocate()
|
|
|
03bb49 |
|
|
|
03bb49 |
Says ubsan:
|
|
|
03bb49 |
|
|
|
03bb49 |
qqmljsfixedpoolarray_p.h:90:19: runtime error: null pointer passed as argument 2, which is declared to never be null
|
|
|
03bb49 |
|
|
|
03bb49 |
Fix, like in so many other places, by a size check.
|
|
|
03bb49 |
|
|
|
03bb49 |
Pick-to: 6.3 6.2 5.15
|
|
|
03bb49 |
Change-Id: I9181d6ecb467c2dc726978ce7f93b35a6bf2f944
|
|
|
03bb49 |
Reviewed-by: Lars Knoll <lars.knoll@qt.io>
|
|
|
03bb49 |
(cherry picked from commit d74e931f3fc2587ac6d1e2930acbbe54ea5be2b5)
|
|
|
03bb49 |
---
|
|
|
03bb49 |
src/qml/common/qqmljsfixedpoolarray_p.h | 2 +-
|
|
|
03bb49 |
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
|
03bb49 |
|
|
|
03bb49 |
diff --git a/src/qml/common/qqmljsfixedpoolarray_p.h b/src/qml/common/qqmljsfixedpoolarray_p.h
|
|
|
03bb49 |
index b65b994d6c..15a8cd6878 100644
|
|
|
03bb49 |
--- a/src/qml/common/qqmljsfixedpoolarray_p.h
|
|
|
03bb49 |
+++ b/src/qml/common/qqmljsfixedpoolarray_p.h
|
|
|
03bb49 |
@@ -86,7 +86,7 @@ public:
|
|
|
03bb49 |
if (QTypeInfo<T>::isComplex) {
|
|
|
03bb49 |
for (int i = 0; i < count; ++i)
|
|
|
03bb49 |
new (data + i) T(vector.at(i));
|
|
|
03bb49 |
- } else {
|
|
|
03bb49 |
+ } else if (count) {
|
|
|
03bb49 |
memcpy(data, static_cast<const void*>(vector.constData()), count * sizeof(T));
|
|
|
03bb49 |
}
|
|
|
03bb49 |
}
|
|
|
03bb49 |
--
|
|
|
03bb49 |
2.35.1
|
|
|
03bb49 |
|