vim-patch:8.2.3779: using freed memory when defining a user command recursively (#17688)

Problem:    Using freed memory when defining a user command from a user
            command.
Solution:   Do not use the command pointer after executing the command.
            (closes vim/vim#9318)
205f29c3e9
This commit is contained in:
Sean Dewar 2022-03-12 08:25:28 +00:00 committed by GitHub
parent 08d9d74fd9
commit ab456bc304
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 28 additions and 2 deletions

View File

@ -6230,7 +6230,6 @@ static void do_ucmd(exarg_T *eap)
size_t split_len = 0; size_t split_len = 0;
char_u *split_buf = NULL; char_u *split_buf = NULL;
ucmd_T *cmd; ucmd_T *cmd;
const sctx_T save_current_sctx = current_sctx;
if (eap->cmdidx == CMD_USER) { if (eap->cmdidx == CMD_USER) {
cmd = USER_CMD(eap->useridx); cmd = USER_CMD(eap->useridx);
@ -6320,12 +6319,19 @@ static void do_ucmd(exarg_T *eap)
buf = xmalloc(totlen + 1); buf = xmalloc(totlen + 1);
} }
sctx_T save_current_sctx;
bool restore_current_sctx = false;
if ((cmd->uc_argt & EX_KEEPSCRIPT) == 0) { if ((cmd->uc_argt & EX_KEEPSCRIPT) == 0) {
restore_current_sctx = true;
save_current_sctx = current_sctx;
current_sctx.sc_sid = cmd->uc_script_ctx.sc_sid; current_sctx.sc_sid = cmd->uc_script_ctx.sc_sid;
} }
(void)do_cmdline(buf, eap->getline, eap->cookie, (void)do_cmdline(buf, eap->getline, eap->cookie,
DOCMD_VERBOSE|DOCMD_NOWAIT|DOCMD_KEYTYPED); DOCMD_VERBOSE|DOCMD_NOWAIT|DOCMD_KEYTYPED);
if ((cmd->uc_argt & EX_KEEPSCRIPT) == 0) {
// Careful: Do not use "cmd" here, it may have become invalid if a user
// command was added.
if (restore_current_sctx) {
current_sctx = save_current_sctx; current_sctx = save_current_sctx;
} }
xfree(buf); xfree(buf);

View File

@ -572,4 +572,24 @@ func Test_delcommand_buffer()
call assert_equal(0, exists(':Global')) call assert_equal(0, exists(':Global'))
endfunc endfunc
func DefCmd(name)
if len(a:name) > 30
return
endif
exe 'command ' .. a:name .. ' call DefCmd("' .. a:name .. 'x")'
echo a:name
exe a:name
endfunc
func Test_recursive_define()
call DefCmd('Command')
let name = 'Command'
while len(name) < 30
exe 'delcommand ' .. name
let name ..= 'x'
endwhile
endfunc
" vim: shiftwidth=2 sts=2 expandtab " vim: shiftwidth=2 sts=2 expandtab