Skip to content

Commit

Permalink
Reland "[libclang] Always Dup in createRef(StringRef)" (llvm#127078)
Browse files Browse the repository at this point in the history
Reverts llvm#127076 to reland llvm#125020.

Use-after-free should be fixed here llvm#127063
  • Loading branch information
vitalybuka authored and joaosaffran committed Feb 27, 2025
1 parent 9d51e94 commit 8355861
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 13 deletions.
3 changes: 3 additions & 0 deletions clang/docs/ReleaseNotes.rst
Original file line number Diff line number Diff line change
Expand Up @@ -266,6 +266,9 @@ clang-format
libclang
--------

- Fixed a buffer overflow in ``CXString`` implementation. The fix may result in
increased memory allocation.

Code Completion
---------------

Expand Down
14 changes: 1 addition & 13 deletions clang/tools/libclang/CXString.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -87,19 +87,7 @@ CXString createRef(StringRef String) {
if (String.empty())
return createEmpty();

// If the string is not nul-terminated, we have to make a copy.

// FIXME: This is doing a one past end read, and should be removed! For memory
// we don't manage, the API string can become unterminated at any time outside
// our control.

if (String.data()[String.size()] != 0)
return createDup(String);

CXString Result;
Result.data = String.data();
Result.private_flags = (unsigned) CXS_Unmanaged;
return Result;
return createDup(String);
}

CXString createDup(StringRef String) {
Expand Down

0 comments on commit 8355861

Please sign in to comment.