Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[C++] Fixing use-after-free and constructor bugs in UnAckedMessageTra…
…ckerEnabled (#11630) * [C++] Fix an off-by-one error in my original change from commit 83f0345. This was caught by ASAN in my company's build system. * [C++] Fixing use-after-free and constructor bugs in UnAckedMessageTrackerEnabled This is very similar to a previous fix I submitted in commit 87ebe80. It's the same basic problem, but this class isn't part of the HandlerBase hierarchy, so it needs an independent fix. Essentially, when we create Boost ASIO timer objects from a connection pointer, they maintain a bare reference to the corresponding io_service object inside the connection object. When the destructor runs, we need to destroy the timer *before* the connection object. Keeping the correct order of these member variables is crucial to ensure we don't hit a use-after-free scenario. This was crashing some of our service code in rare circumstances, and is easily caught with Valgrind or ASAN. I also noticed a rather serious bug in one of the UnAckedMessageTrackerEnabled constructors: I believe the intent here was to use the c++11 "delegating constructors" feature, but I think it's written using the Java style, which doesn't work in C++ (see https://stackoverflow.com/questions/13961037/delegate-constructor-c). The semantics of the existing code would just create a new, separate UnAckedMessageTrackerEnabled on the stack in the constructor scope, then immediately destroy it! I corrected the syntax to ensure this works correctly, and fixed up the other constructor to properly use C++ initializer list syntax. Finally, I removed some dangerous c-style casts (which should *never* be used) in favor of C++ static_cast. * [C++] Applied clang-format to previous change * [C++] Apparently clang-format didn't like this one either....
- Loading branch information