diff options
author | Simon Hausmann <simon.hausmann@digia.com> | 2014-03-04 16:15:26 +0100 |
---|---|---|
committer | The Qt Project <gerrit-noreply@qt-project.org> | 2014-03-05 15:01:07 +0100 |
commit | e4e4a7912b03499a20f25e261e1c515aab17e5a8 (patch) | |
tree | 412e643b91e0445b64fe4389c51359bb17195be1 /src/qml/compiler/qqmltypecompiler.cpp | |
parent | 0d84dab38059345f51e8318d2474068e817ac007 (diff) |
[new compiler] Fix invalid memory reads when JS closures outlive QML types
If QQmlCompiledData gets destroyed while somebody still has refcount on the
QV4::CompiledData::CompilationUnit, then unit's _data_ would be freed already
by ~QQmlCompiledData. Given that compilationUnit->data is pointing to the same
malloc'ed address as QQmlCompiledData::qmlUnit, we can just let the
CompilationUnit always own the data.
Fixes tst_qquickloader and makes it possible to run the qquickcomponent tests.
Change-Id: Ie3f3e5335139236d7c2524a327665bda0a9cc847
Reviewed-by: Lars Knoll <lars.knoll@digia.com>
Diffstat (limited to 'src/qml/compiler/qqmltypecompiler.cpp')
-rw-r--r-- | src/qml/compiler/qqmltypecompiler.cpp | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/src/qml/compiler/qqmltypecompiler.cpp b/src/qml/compiler/qqmltypecompiler.cpp index dfea506c8f..0cab2c4397 100644 --- a/src/qml/compiler/qqmltypecompiler.cpp +++ b/src/qml/compiler/qqmltypecompiler.cpp @@ -215,7 +215,8 @@ bool QQmlTypeCompiler::compile() if (jsUnit) { Q_ASSERT(!jsUnit->data); - jsUnit->ownsData = false; + Q_ASSERT((void*)qmlUnit == (void*)&qmlUnit->header); + // The js unit owns the data and will free the qml unit. jsUnit->data = &qmlUnit->header; } |