From c38639089f0e17a3da40dca03fecac88f5d89ba9 Mon Sep 17 00:00:00 2001 From: Marc Mutz Date: Thu, 9 Dec 2021 22:53:48 +0100 Subject: [PATCH] QVarLengthArray: assert that the range passed to erase() is valid We already checked that the two iterators, indvidually, are valid, but we didn't check that the range formed by them is valid, namely that the end iterator is reachable from the start iterator. Add an assert, because if the range isn't valid, we run into UB in the std::move() algorithm two lines later. Qt 5.15 uses std::copy() here, which has the same precondition, so the assertion would make sense there, too. Pick-to: 6.2 5.15 Change-Id: I90b7e846455ff86383a8971bea908036684961d8 Reviewed-by: Thiago Macieira --- src/corelib/tools/qvarlengtharray.h | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/corelib/tools/qvarlengtharray.h b/src/corelib/tools/qvarlengtharray.h index 07add066af..8b92ded0e3 100644 --- a/src/corelib/tools/qvarlengtharray.h +++ b/src/corelib/tools/qvarlengtharray.h @@ -896,6 +896,8 @@ Q_OUTOFLINE_TEMPLATE auto QVLABase::erase(const_iterator abegin, const_iterat if (n == 0) // avoid UB in std::move() below return data() + f; + Q_ASSERT(n > 0); // aend must be reachable from abegin + if constexpr (QTypeInfo::isComplex) { std::move(begin() + l, end(), QT_MAKE_CHECKED_ARRAY_ITERATOR(begin() + f, size() - f)); std::destroy(end() - n, end());