mirror of
https://github.com/qelectrotech/qelectrotech-source-mirror.git
synced 2026-10-11 06:34:14 +02:00
Fix the double free when a deleted cable is undone and edited again
Deleting a cable and pressing Ctrl+Z twice leaves the cable out of the project while AddCableCommand still stands and still thinks it has to clean that cable up. The next edit of any kind makes the stack throw the undone commands away: ~RemoveCableCommand frees the cable, and ~AddCableCommand frees the same memory again. A plain build hides it, AddressSanitizer reports it as a heap-use-after-free in addcablecommand.cpp (blocking review comment by ispyisail). AddCableCommand now holds the cable as a QPointer, which is what RemoveCableCommand already did: whoever of the two runs first frees it, the other one sees a null pointer and has nothing left to do, in either order of destruction. The destructor also stopped dereferencing project() without checking it, which it did on that very line. Covered by tst_cableundointegration, a probe linked against the application's objects the way the other integration probes are. It draws a cable, deletes it, undoes twice and pushes a further edit -- the sequence which used to crash. Verified in both directions: with the raw pointer the probe dies with SIGSEGV inside ~AddCableCommand called from QUndoStack::push, with the QPointer it prints its PASS line.
This commit is contained in:
@@ -87,11 +87,19 @@ AddCableCommand::AddCableCommand(Cable *cable,
|
||||
Whatever the stack leaves behind has to be cleaned up here: a cable
|
||||
which is not held by the project any more belongs to this command,
|
||||
and so does a line which never made it onto a folio.
|
||||
|
||||
The cable is a QPointer, so if another command took it away first it
|
||||
is already null here and there is nothing left to do -- which is
|
||||
exactly the point, since following a raw pointer here meant freeing
|
||||
the same cable a second time.
|
||||
*/
|
||||
AddCableCommand::~AddCableCommand()
|
||||
{
|
||||
if (m_cable && m_own_cable && !project()->cables().contains(m_cable)) {
|
||||
delete m_cable;
|
||||
if (m_cable && m_own_cable) {
|
||||
QETProject *proj = project();
|
||||
if (!proj || !proj->cables().contains(m_cable.data())) {
|
||||
delete m_cable.data();
|
||||
}
|
||||
}
|
||||
if (m_part && !m_part->scene()) {
|
||||
delete m_part;
|
||||
|
||||
Reference in New Issue
Block a user