Skip to content

fix: Avoid premature release for external pointers - #2

Open
krlmlr wants to merge 12 commits into
b-extptr-leakfrom
claude/b-extptr-leak-42ve6t
Open

fix: Avoid premature release for external pointers#2
krlmlr wants to merge 12 commits into
b-extptr-leakfrom
claude/b-extptr-leak-42ve6t

Conversation

@krlmlr

@krlmlr krlmlr commented Aug 17, 2026

Copy link
Copy Markdown
Owner

Patch b-extptr-leak of the stack.

external_pointer's move constructor and move assignment operator both went through reset(rhs.release()). release() hands back the raw pointer and drops the SEXP that carried it, so the attributes on that SEXP were lost across a move, and reset() then built a fresh external pointer around the raw address — releasing the old one before the new owner had taken it over.

Moving the data_ member directly keeps the SEXP itself, attributes and all, and clearing the right-hand side afterwards is what makes it a move. data_ is a cpp11::sexp, which owns the protection, so this is correct even for self-move.

The move assignment operator was also missing its return *this; — it was declared to return a reference and fell off the end.

Tests in cpp11test/src/test-external_pointer.cpp cover attribute preservation through both the move constructor and move assignment.

Verification

cpp11test's external_pointer-C++ suite passes, as does the rest of the C++ suite, against an install of this branch.

Squashed from five commits on the original b-extptr-leak, three of which were "Remove", "Clarify" and "Formatting". The original branch is untouched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01K8MneV8KqHYUuC8fWV3X5Q


Generated by Claude Code

DavisVaughan and others added 12 commits April 3, 2026 13:09
* Don't rely on transitive include of `"fmt/core.h"`

We got it through `cpp11/protect.hpp`, but we should not rely on that

* Correctly use `fmt::runtime()` on runtime strings passed to `fmt::format()`

In fmt, there is a `FMT_CONSTEVAL` macro that resolves to `consteval` on "new enough" C++ (otherwise it doesn't do anything). For R 4.6+, the default C++ used is finally "new enough" (`__cplusplus > 201703L`).

This causes all `fmt::format()` calls to require a constant expression for `const char*` and `std::string&` input, which we are not currently doing via `fmt_arg`.

We have a runtime provided string, which must now be wrapped in `fmt::runtime()`, which is what we should have been doing all along.

* Add `r_ns_env()` and use in `get_namespace()`

Throwing an informative (and tested!) error when we can't find the package namespace

* Define `RCPP_NO_R_HEADERS_CHECK` before all `#include <Rcpp.h>` usage

`#include <cpp11/R.hpp>` sets everything up the right way, and otherwise we get a warning from Rcpp which doesn't seem to end up being relevant for this use case

* Use `r_env_has()` + `r_env_get()`

To avoid triggering a NOTE about usage of `Rf_findVarInFrame3()` on R 4.5, where technically we had the tools to avoid that
* Teach `cpp_source()` how to source multiple files

* NEWS bullet

* Link to PR
…violations (r-lib#493)

* Add failing test

* Use tag types to generate attribute specific internals

* NEWS bullet

* Formatting
* Update `cran-comments.md`

* Increment version number to 0.5.5
The move constructor and move assignment operator went through
`reset(rhs.release())`, which dropped the SEXP's attributes and released
the pointer before the new owner had taken it over. Move the `data_`
member directly instead, and clear the right-hand side afterwards.

Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
@krlmlr
krlmlr changed the base branch from main to claude/main-42ve6t August 17, 2026 21:12
@krlmlr
krlmlr changed the base branch from claude/main-42ve6t to b-extptr-leak August 17, 2026 21:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants