eaec1b0
To: vim-dev@vim.org
eaec1b0
Subject: About patch 7.1.130
eaec1b0
Fcc: outbox
eaec1b0
From: Bram Moolenaar <Bram@moolenaar.net>
eaec1b0
Mime-Version: 1.0
eaec1b0
Content-Type: text/plain; charset=ISO-8859-1
eaec1b0
Content-Transfer-Encoding: 8bit
eaec1b0
------------
eaec1b0
eaec1b0
Patch 7.1.130
eaec1b0
Problem:    Crash with specific order of undo and redo. (A.Politz)
eaec1b0
Solution:   Clear and adjust pointers properly.  Add u_check() for debugging.
eaec1b0
Files:	    src/undo.c, src/structs.h
eaec1b0
eaec1b0
eaec1b0
*** ../vim-7.1.129/src/undo.c	Thu May 10 20:01:43 2007
eaec1b0
--- src/undo.c	Mon Oct  1 22:49:16 2007
eaec1b0
***************
eaec1b0
*** 76,81 ****
eaec1b0
--- 76,87 ----
eaec1b0
   * buffer is unloaded.
eaec1b0
   */
eaec1b0
  
eaec1b0
+ /* Uncomment the next line for including the u_check() function.  This warns
eaec1b0
+  * for errors in the debug information. */
eaec1b0
+ /* #define U_DEBUG 1 */
eaec1b0
+ #define UH_MAGIC 0x18dade	/* value for uh_magic when in use */
eaec1b0
+ #define UE_MAGIC 0xabc123	/* value for ue_magic when in use */
eaec1b0
+ 
eaec1b0
  #include "vim.h"
eaec1b0
  
eaec1b0
  /* See below: use malloc()/free() for memory management. */
eaec1b0
***************
eaec1b0
*** 113,118 ****
eaec1b0
--- 119,213 ----
eaec1b0
   */
eaec1b0
  static int	undo_undoes = FALSE;
eaec1b0
  
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+ /*
eaec1b0
+  * Check the undo structures for being valid.  Print a warning when something
eaec1b0
+  * looks wrong.
eaec1b0
+  */
eaec1b0
+ static int seen_b_u_curhead;
eaec1b0
+ static int seen_b_u_newhead;
eaec1b0
+ static int header_count;
eaec1b0
+ 
eaec1b0
+     static void
eaec1b0
+ u_check_tree(u_header_T *uhp,
eaec1b0
+ 	u_header_T *exp_uh_next,
eaec1b0
+ 	u_header_T *exp_uh_alt_prev)
eaec1b0
+ {
eaec1b0
+     u_entry_T *uep;
eaec1b0
+ 
eaec1b0
+     if (uhp == NULL)
eaec1b0
+ 	return;
eaec1b0
+     ++header_count;
eaec1b0
+     if (uhp == curbuf->b_u_curhead && ++seen_b_u_curhead > 1)
eaec1b0
+     {
eaec1b0
+ 	EMSG("b_u_curhead found twice (looping?)");
eaec1b0
+ 	return;
eaec1b0
+     }
eaec1b0
+     if (uhp == curbuf->b_u_newhead && ++seen_b_u_newhead > 1)
eaec1b0
+     {
eaec1b0
+ 	EMSG("b_u_newhead found twice (looping?)");
eaec1b0
+ 	return;
eaec1b0
+     }
eaec1b0
+ 
eaec1b0
+     if (uhp->uh_magic != UH_MAGIC)
eaec1b0
+ 	EMSG("uh_magic wrong (may be using freed memory)");
eaec1b0
+     else
eaec1b0
+     {
eaec1b0
+ 	/* Check pointers back are correct. */
eaec1b0
+ 	if (uhp->uh_next != exp_uh_next)
eaec1b0
+ 	{
eaec1b0
+ 	    EMSG("uh_next wrong");
eaec1b0
+ 	    smsg((char_u *)"expected: 0x%x, actual: 0x%x",
eaec1b0
+ 						   exp_uh_next, uhp->uh_next);
eaec1b0
+ 	}
eaec1b0
+ 	if (uhp->uh_alt_prev != exp_uh_alt_prev)
eaec1b0
+ 	{
eaec1b0
+ 	    EMSG("uh_alt_prev wrong");
eaec1b0
+ 	    smsg((char_u *)"expected: 0x%x, actual: 0x%x",
eaec1b0
+ 					   exp_uh_alt_prev, uhp->uh_alt_prev);
eaec1b0
+ 	}
eaec1b0
+ 
eaec1b0
+ 	/* Check the undo tree at this header. */
eaec1b0
+ 	for (uep = uhp->uh_entry; uep != NULL; uep = uep->ue_next)
eaec1b0
+ 	{
eaec1b0
+ 	    if (uep->ue_magic != UE_MAGIC)
eaec1b0
+ 	    {
eaec1b0
+ 		EMSG("ue_magic wrong (may be using freed memory)");
eaec1b0
+ 		break;
eaec1b0
+ 	    }
eaec1b0
+ 	}
eaec1b0
+ 
eaec1b0
+ 	/* Check the next alt tree. */
eaec1b0
+ 	u_check_tree(uhp->uh_alt_next, uhp->uh_next, uhp);
eaec1b0
+ 
eaec1b0
+ 	/* Check the next header in this branch. */
eaec1b0
+ 	u_check_tree(uhp->uh_prev, uhp, NULL);
eaec1b0
+     }
eaec1b0
+ }
eaec1b0
+ 
eaec1b0
+     void
eaec1b0
+ u_check(int newhead_may_be_NULL)
eaec1b0
+ {
eaec1b0
+     seen_b_u_newhead = 0;
eaec1b0
+     seen_b_u_curhead = 0;
eaec1b0
+     header_count = 0;
eaec1b0
+ 
eaec1b0
+     u_check_tree(curbuf->b_u_oldhead, NULL, NULL);
eaec1b0
+ 
eaec1b0
+     if (seen_b_u_newhead == 0 && curbuf->b_u_oldhead != NULL
eaec1b0
+ 	    && !(newhead_may_be_NULL && curbuf->b_u_newhead == NULL))
eaec1b0
+ 	EMSGN("b_u_newhead invalid: 0x%x", curbuf->b_u_newhead);
eaec1b0
+     if (curbuf->b_u_curhead != NULL && seen_b_u_curhead == 0)
eaec1b0
+ 	EMSGN("b_u_curhead invalid: 0x%x", curbuf->b_u_curhead);
eaec1b0
+     if (header_count != curbuf->b_u_numhead)
eaec1b0
+     {
eaec1b0
+ 	EMSG("b_u_numhead invalid");
eaec1b0
+ 	smsg((char_u *)"expected: %ld, actual: %ld",
eaec1b0
+ 			       (long)header_count, (long)curbuf->b_u_numhead);
eaec1b0
+     }
eaec1b0
+ }
eaec1b0
+ #endif
eaec1b0
+ 
eaec1b0
  /*
eaec1b0
   * Save the current line for both the "u" and "U" command.
eaec1b0
   * Returns OK or FAIL.
eaec1b0
***************
eaec1b0
*** 243,248 ****
eaec1b0
--- 338,346 ----
eaec1b0
      if (!undo_allowed())
eaec1b0
  	return FAIL;
eaec1b0
  
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+     u_check(FALSE);
eaec1b0
+ #endif
eaec1b0
  #ifdef FEAT_NETBEANS_INTG
eaec1b0
      /*
eaec1b0
       * Netbeans defines areas that cannot be modified.  Bail out here when
eaec1b0
***************
eaec1b0
*** 294,299 ****
eaec1b0
--- 392,400 ----
eaec1b0
  	    uhp = (u_header_T *)U_ALLOC_LINE((unsigned)sizeof(u_header_T));
eaec1b0
  	    if (uhp == NULL)
eaec1b0
  		goto nomem;
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+ 	    uhp->uh_magic = UH_MAGIC;
eaec1b0
+ #endif
eaec1b0
  	}
eaec1b0
  	else
eaec1b0
  	    uhp = NULL;
eaec1b0
***************
eaec1b0
*** 316,323 ****
eaec1b0
  	{
eaec1b0
  	    u_header_T	    *uhfree = curbuf->b_u_oldhead;
eaec1b0
  
eaec1b0
! 	    /* If there is no branch only free one header. */
eaec1b0
! 	    if (uhfree->uh_alt_next == NULL)
eaec1b0
  		u_freeheader(curbuf, uhfree, &old_curhead);
eaec1b0
  	    else
eaec1b0
  	    {
eaec1b0
--- 417,427 ----
eaec1b0
  	{
eaec1b0
  	    u_header_T	    *uhfree = curbuf->b_u_oldhead;
eaec1b0
  
eaec1b0
! 	    if (uhfree == old_curhead)
eaec1b0
! 		/* Can't reconnect the branch, delete all of it. */
eaec1b0
! 		u_freebranch(curbuf, uhfree, &old_curhead);
eaec1b0
! 	    else if (uhfree->uh_alt_next == NULL)
eaec1b0
! 		/* There is no branch, only free one header. */
eaec1b0
  		u_freeheader(curbuf, uhfree, &old_curhead);
eaec1b0
  	    else
eaec1b0
  	    {
eaec1b0
***************
eaec1b0
*** 326,331 ****
eaec1b0
--- 430,438 ----
eaec1b0
  		    uhfree = uhfree->uh_alt_next;
eaec1b0
  		u_freebranch(curbuf, uhfree, &old_curhead);
eaec1b0
  	    }
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+ 	    u_check(TRUE);
eaec1b0
+ #endif
eaec1b0
  	}
eaec1b0
  
eaec1b0
  	if (uhp == NULL)		/* no undo at all */
eaec1b0
***************
eaec1b0
*** 478,483 ****
eaec1b0
--- 585,593 ----
eaec1b0
      uep = (u_entry_T *)U_ALLOC_LINE((unsigned)sizeof(u_entry_T));
eaec1b0
      if (uep == NULL)
eaec1b0
  	goto nomem;
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+     uep->ue_magic = UE_MAGIC;
eaec1b0
+ #endif
eaec1b0
  
eaec1b0
      uep->ue_size = size;
eaec1b0
      uep->ue_top = top;
eaec1b0
***************
eaec1b0
*** 525,530 ****
eaec1b0
--- 635,643 ----
eaec1b0
      curbuf->b_u_synced = FALSE;
eaec1b0
      undo_undoes = FALSE;
eaec1b0
  
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+     u_check(FALSE);
eaec1b0
+ #endif
eaec1b0
      return OK;
eaec1b0
  
eaec1b0
  nomem:
eaec1b0
***************
eaec1b0
*** 955,960 ****
eaec1b0
--- 1068,1076 ----
eaec1b0
      int		empty_buffer;		    /* buffer became empty */
eaec1b0
      u_header_T	*curhead = curbuf->b_u_curhead;
eaec1b0
  
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+     u_check(FALSE);
eaec1b0
+ #endif
eaec1b0
      old_flags = curhead->uh_flags;
eaec1b0
      new_flags = (curbuf->b_changed ? UH_CHANGED : 0) +
eaec1b0
  	       ((curbuf->b_ml.ml_flags & ML_EMPTY) ? UH_EMPTYBUF : 0);
eaec1b0
***************
eaec1b0
*** 1186,1191 ****
eaec1b0
--- 1302,1310 ----
eaec1b0
      /* The timestamp can be the same for multiple changes, just use the one of
eaec1b0
       * the undone/redone change. */
eaec1b0
      curbuf->b_u_seq_time = curhead->uh_time;
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+     u_check(FALSE);
eaec1b0
+ #endif
eaec1b0
  }
eaec1b0
  
eaec1b0
  /*
eaec1b0
***************
eaec1b0
*** 1515,1521 ****
eaec1b0
  }
eaec1b0
  
eaec1b0
  /*
eaec1b0
!  * Free one header and its entry list and adjust the pointers.
eaec1b0
   */
eaec1b0
      static void
eaec1b0
  u_freeheader(buf, uhp, uhpp)
eaec1b0
--- 1634,1640 ----
eaec1b0
  }
eaec1b0
  
eaec1b0
  /*
eaec1b0
!  * Free one header "uhp" and its entry list and adjust the pointers.
eaec1b0
   */
eaec1b0
      static void
eaec1b0
  u_freeheader(buf, uhp, uhpp)
eaec1b0
***************
eaec1b0
*** 1523,1528 ****
eaec1b0
--- 1642,1649 ----
eaec1b0
      u_header_T	    *uhp;
eaec1b0
      u_header_T	    **uhpp;	/* if not NULL reset when freeing this header */
eaec1b0
  {
eaec1b0
+     u_header_T	    *uhap;
eaec1b0
+ 
eaec1b0
      /* When there is an alternate redo list free that branch completely,
eaec1b0
       * because we can never go there. */
eaec1b0
      if (uhp->uh_alt_next != NULL)
eaec1b0
***************
eaec1b0
*** 1540,1546 ****
eaec1b0
      if (uhp->uh_prev == NULL)
eaec1b0
  	buf->b_u_newhead = uhp->uh_next;
eaec1b0
      else
eaec1b0
! 	uhp->uh_prev->uh_next = uhp->uh_next;
eaec1b0
  
eaec1b0
      u_freeentries(buf, uhp, uhpp);
eaec1b0
  }
eaec1b0
--- 1661,1668 ----
eaec1b0
      if (uhp->uh_prev == NULL)
eaec1b0
  	buf->b_u_newhead = uhp->uh_next;
eaec1b0
      else
eaec1b0
! 	for (uhap = uhp->uh_prev; uhap != NULL; uhap = uhap->uh_alt_next)
eaec1b0
! 	    uhap->uh_next = uhp->uh_next;
eaec1b0
  
eaec1b0
      u_freeentries(buf, uhp, uhpp);
eaec1b0
  }
eaec1b0
***************
eaec1b0
*** 1585,1590 ****
eaec1b0
--- 1707,1714 ----
eaec1b0
      /* Check for pointers to the header that become invalid now. */
eaec1b0
      if (buf->b_u_curhead == uhp)
eaec1b0
  	buf->b_u_curhead = NULL;
eaec1b0
+     if (buf->b_u_newhead == uhp)
eaec1b0
+ 	buf->b_u_newhead = NULL;  /* freeing the newest entry */
eaec1b0
      if (uhpp != NULL && uhp == *uhpp)
eaec1b0
  	*uhpp = NULL;
eaec1b0
  
eaec1b0
***************
eaec1b0
*** 1594,1599 ****
eaec1b0
--- 1718,1726 ----
eaec1b0
  	u_freeentry(uep, uep->ue_size);
eaec1b0
      }
eaec1b0
  
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+     uhp->uh_magic = 0;
eaec1b0
+ #endif
eaec1b0
      U_FREE_LINE((char_u *)uhp);
eaec1b0
      --buf->b_u_numhead;
eaec1b0
  }
eaec1b0
***************
eaec1b0
*** 1609,1614 ****
eaec1b0
--- 1736,1744 ----
eaec1b0
      while (n > 0)
eaec1b0
  	U_FREE_LINE(uep->ue_array[--n]);
eaec1b0
      U_FREE_LINE((char_u *)uep->ue_array);
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+     uep->ue_magic = 0;
eaec1b0
+ #endif
eaec1b0
      U_FREE_LINE((char_u *)uep);
eaec1b0
  }
eaec1b0
  
eaec1b0
*** ../vim-7.1.129/src/structs.h	Sun Aug 12 15:50:26 2007
eaec1b0
--- src/structs.h	Sat Sep 29 15:03:38 2007
eaec1b0
***************
eaec1b0
*** 278,283 ****
eaec1b0
--- 278,286 ----
eaec1b0
      linenr_T	ue_lcount;	/* linecount when u_save called */
eaec1b0
      char_u	**ue_array;	/* array of lines in undo block */
eaec1b0
      long	ue_size;	/* number of lines in ue_array */
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+     int		ue_magic;	/* magic number to check allocation */
eaec1b0
+ #endif
eaec1b0
  };
eaec1b0
  
eaec1b0
  struct u_header
eaec1b0
***************
eaec1b0
*** 300,305 ****
eaec1b0
--- 303,311 ----
eaec1b0
      visualinfo_T uh_visual;	/* Visual areas before undo/after redo */
eaec1b0
  #endif
eaec1b0
      time_t	uh_time;	/* timestamp when the change was made */
eaec1b0
+ #ifdef U_DEBUG
eaec1b0
+     int		uh_magic;	/* magic number to check allocation */
eaec1b0
+ #endif
eaec1b0
  };
eaec1b0
  
eaec1b0
  /* values for uh_flags */
eaec1b0
*** ../vim-7.1.129/src/version.c	Mon Oct  1 20:33:45 2007
eaec1b0
--- src/version.c	Mon Oct  1 22:50:23 2007
eaec1b0
***************
eaec1b0
*** 668,669 ****
eaec1b0
--- 668,671 ----
eaec1b0
  {   /* Add new patch number below this line */
eaec1b0
+ /**/
eaec1b0
+     130,
eaec1b0
  /**/
eaec1b0
eaec1b0
-- 
eaec1b0
FIRST SOLDIER:  So they wouldn't be able to bring a coconut back anyway.
eaec1b0
SECOND SOLDIER: Wait a minute! Suppose two swallows carried it together?
eaec1b0
FIRST SOLDIER:  No, they'd have to have it on a line.
eaec1b0
                 "Monty Python and the Holy Grail" PYTHON (MONTY) PICTURES LTD
eaec1b0
eaec1b0
 /// Bram Moolenaar -- Bram@Moolenaar.net -- http://www.Moolenaar.net   \\\
eaec1b0
///        sponsor Vim, vote for features -- http://www.Vim.org/sponsor/ \\\
eaec1b0
\\\        download, build and distribute -- http://www.A-A-P.org        ///
eaec1b0
 \\\            help me help AIDS victims -- http://ICCF-Holland.org    ///