-
Notifications
You must be signed in to change notification settings - Fork 13k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Rollup merge of #123803 - Sp00ph:shrink_to_fix, r=Mark-Simulacrum
Fix `VecDeque::shrink_to` UB when `handle_alloc_error` unwinds. Fixes #123369 For `VecDeque` it's relatively simple to restore the buffer into a consistent state so this PR does just that. Note that with its current implementation, `shrink_to` may change the internal arrangement of elements in the buffer, so e.g. `[D, <uninit>, A, B, C]` will become `[<uninit>, A, B, C, D]` and `[<uninit>, <uninit>, A, B, C]` may become `[B, C, <uninit>, <uninit>, A]` if `shrink_to` unwinds. This shouldn't be an issue though as we don't make any guarantees about the stability of the internal buffer arrangement (and this case is impossible to hit on stable anyways). This PR also includes a test with code adapted from #123369 which fails without the new `shrink_to` code. Does this suffice or do we maybe need more exhaustive tests like in #108475? cc `@Amanieu` `@rustbot` label +T-libs
- Loading branch information
Showing
3 changed files
with
118 additions
and
1 deletion.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,49 @@ | ||
#![feature(alloc_error_hook, allocator_api)] | ||
|
||
use std::{ | ||
alloc::{set_alloc_error_hook, AllocError, Allocator, Layout, System}, | ||
collections::VecDeque, | ||
panic::{catch_unwind, AssertUnwindSafe}, | ||
ptr::NonNull, | ||
}; | ||
|
||
#[test] | ||
fn test_shrink_to_unwind() { | ||
// This tests that `shrink_to` leaves the deque in a consistent state when | ||
// the call to `RawVec::shrink_to_fit` unwinds. The code is adapted from #123369 | ||
// but changed to hopefully not have any UB even if the test fails. | ||
|
||
struct BadAlloc; | ||
|
||
unsafe impl Allocator for BadAlloc { | ||
fn allocate(&self, l: Layout) -> Result<NonNull<[u8]>, AllocError> { | ||
// We allocate zeroed here so that the whole buffer of the deque | ||
// is always initialized. That way, even if the deque is left in | ||
// an inconsistent state, no uninitialized memory should be accessed. | ||
System.allocate_zeroed(l) | ||
} | ||
|
||
unsafe fn deallocate(&self, ptr: NonNull<u8>, layout: Layout) { | ||
unsafe { System.deallocate(ptr, layout) } | ||
} | ||
|
||
unsafe fn shrink( | ||
&self, | ||
_ptr: NonNull<u8>, | ||
_old_layout: Layout, | ||
_new_layout: Layout, | ||
) -> Result<NonNull<[u8]>, AllocError> { | ||
Err(AllocError) | ||
} | ||
} | ||
|
||
set_alloc_error_hook(|_| panic!("alloc error")); | ||
|
||
let mut v = VecDeque::with_capacity_in(15, BadAlloc); | ||
v.push_back(1); | ||
v.push_front(2); | ||
// This should unwind because it calls `BadAlloc::shrink` and then `handle_alloc_error` which unwinds. | ||
assert!(catch_unwind(AssertUnwindSafe(|| v.shrink_to_fit())).is_err()); | ||
// This should only pass if the deque is left in a consistent state. | ||
assert_eq!(v, [2, 1]); | ||
} |