summaryrefslogtreecommitdiff
path: root/memory
diff options
context:
space:
mode:
authorjorton <jorton@13f79535-47bb-0310-9956-ffa450edef68>2005-10-25 13:14:14 +0000
committerjorton <jorton@13f79535-47bb-0310-9956-ffa450edef68>2005-10-25 13:14:14 +0000
commite80e45ce6f92d6ea173d5e5042629a54d1d7d24c (patch)
tree6721799dc5fe37305b5669fb84dacbdfa2973563 /memory
parent6b8e2ee473ae75d6cd6e8d6b369552b21b246916 (diff)
downloadlibapr-e80e45ce6f92d6ea173d5e5042629a54d1d7d24c.tar.gz
* memory/unix/apr_pools.c (pool_clear_debug): Scribble over blocks
with a poison byte before freeing them to help highlight use-after-free bugs. git-svn-id: http://svn.apache.org/repos/asf/apr/apr/trunk@328355 13f79535-47bb-0310-9956-ffa450edef68
Diffstat (limited to 'memory')
-rw-r--r--memory/unix/apr_pools.c11
1 files changed, 9 insertions, 2 deletions
diff --git a/memory/unix/apr_pools.c b/memory/unix/apr_pools.c
index 13c60a870..4e6200ab9 100644
--- a/memory/unix/apr_pools.c
+++ b/memory/unix/apr_pools.c
@@ -1356,6 +1356,8 @@ APR_DECLARE(void *) apr_pcalloc_debug(apr_pool_t *pool, apr_size_t size,
* Pool creation/destruction (debug)
*/
+#define POOL_POISON_BYTE 'A'
+
static void pool_clear_debug(apr_pool_t *pool, const char *file_line)
{
debug_node_t *node;
@@ -1383,13 +1385,18 @@ static void pool_clear_debug(apr_pool_t *pool, const char *file_line)
/* Clear the user data. */
pool->user_data = NULL;
- /* Free the blocks */
+ /* Free the blocks, scribbling over them first to help highlight
+ * use-after-free issues. */
while ((node = pool->nodes) != NULL) {
pool->nodes = node->next;
- for (index = 0; index < node->index; index++)
+ for (index = 0; index < node->index; index++) {
+ memset(node->beginp[index], POOL_POISON_BYTE,
+ node->endp[index] - node->beginp[index]);
free(node->beginp[index]);
+ }
+ memset(node, POOL_POISON_BYTE, SIZEOF_DEBUG_NODE_T);
free(node);
}