瀏覽代碼

fix pthread_exit from cancellation handler

cancellation frames were not correctly popped, so this usage would not
only loop, but also reuse discarded and invalid parts of the stack.
Rich Felker 14 年之前
父節點
當前提交
1ebde9c3a2
共有 1 個文件被更改,包括 5 次插入5 次删除
  1. 5 5
      src/thread/pthread_create.c

+ 5 - 5
src/thread/pthread_create.c

@@ -18,12 +18,13 @@ weak_alias(dummy_1, __pthread_tsd_run_dtors);
 
 void __pthread_unwind_next(struct __ptcb *cb)
 {
-	pthread_t self;
+	pthread_t self = pthread_self();
 	int n;
 
-	if (cb->__next) longjmp((void *)cb->__next->__jb, 1);
-
-	self = pthread_self();
+	if (cb->__next) {
+		self->cancelbuf = cb->__next->__next;
+		longjmp((void *)cb->__next->__jb, 1);
+	}
 
 	LOCK(&self->exitlock);
 
@@ -104,7 +105,6 @@ int pthread_create(pthread_t *res, const pthread_attr_t *attr, void *(*entry)(vo
 	new->detached = attr->_a_detach;
 	new->attr = *attr;
 	new->unblock_cancel = self->cancel;
-	new->result = PTHREAD_CANCELED;
 	memcpy(new->tlsdesc, self->tlsdesc, sizeof new->tlsdesc);
 	new->tlsdesc[1] = (uintptr_t)new;
 	stack = (void *)((uintptr_t)new-1 & ~(uintptr_t)15);