summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBram Moolenaar <Bram@vim.org>2022-08-22 16:35:45 +0100
committerBram Moolenaar <Bram@vim.org>2022-08-22 16:35:45 +0100
commitadce965162dd89bf29ee0e5baf53652e7515762c (patch)
tree42b5a805c2e14bfb973e96104ae19af41dbeaac9
parent471c0fa3eed4f6207d1cb7636970547bfd2eee26 (diff)
downloadvim-git-adce965162dd89bf29ee0e5baf53652e7515762c.tar.gz
patch 9.0.0246: using freed memory when 'tagfunc' deletes the bufferv9.0.0246
Problem: Using freed memory when 'tagfunc' deletes the buffer. Solution: Make a copy of the tag name.
-rw-r--r--src/tag.c9
-rw-r--r--src/testdir/test_tagfunc.vim12
-rw-r--r--src/version.c2
3 files changed, 22 insertions, 1 deletions
diff --git a/src/tag.c b/src/tag.c
index 8a351cc05..02f0818fe 100644
--- a/src/tag.c
+++ b/src/tag.c
@@ -281,6 +281,7 @@ do_tag(
char_u *buf_ffname = curbuf->b_ffname; // name to use for
// priority computation
int use_tfu = 1;
+ char_u *tofree = NULL;
// remember the matches for the last used tag
static int num_matches = 0;
@@ -630,7 +631,12 @@ do_tag(
* When desired match not found yet, try to find it (and others).
*/
if (use_tagstack)
- name = tagstack[tagstackidx].tagname;
+ {
+ // make a copy, the tagstack may change in 'tagfunc'
+ name = vim_strsave(tagstack[tagstackidx].tagname);
+ vim_free(tofree);
+ tofree = name;
+ }
#if defined(FEAT_QUICKFIX)
else if (g_do_tagpreview != 0)
name = ptag_entry.tagname;
@@ -922,6 +928,7 @@ end_do_tag:
g_do_tagpreview = 0; // don't do tag preview next time
# endif
+ vim_free(tofree);
#ifdef FEAT_CSCOPE
return jumped_to_tag;
#else
diff --git a/src/testdir/test_tagfunc.vim b/src/testdir/test_tagfunc.vim
index 05d8473cf..95826121c 100644
--- a/src/testdir/test_tagfunc.vim
+++ b/src/testdir/test_tagfunc.vim
@@ -389,4 +389,16 @@ func Test_tagfunc_callback()
%bw!
endfunc
+func Test_tagfunc_wipes_buffer()
+ func g:Tag0unc0(t,f,o)
+ bwipe
+ endfunc
+ set tagfunc=g:Tag0unc0
+ new
+ cal assert_fails('tag 0', 'E987:')
+
+ delfunc g:Tag0unc0
+ set tagfunc=
+endfunc
+
" vim: shiftwidth=2 sts=2 expandtab
diff --git a/src/version.c b/src/version.c
index ec381fef2..ec1302df0 100644
--- a/src/version.c
+++ b/src/version.c
@@ -732,6 +732,8 @@ static char *(features[]) =
static int included_patches[] =
{ /* Add new patch number below this line */
/**/
+ 246,
+/**/
245,
/**/
244,