Cleanup if early return from opj_j2k_copy_default_tcp_and_create_tcd().
authorTom Sepez <tsepez@chromium.org>
Mon, 18 May 2015 22:46:54 +0000 (15:46 -0700)
committerTom Sepez <tsepez@chromium.org>
Mon, 18 May 2015 22:46:54 +0000 (15:46 -0700)
commit3b60890f6ee807a8bfc44056443f77603c23e6b0
tree2b573d9f0f62d0a03a5b6e1eeb5e78c4b24ed734
parent3fea540931b6b2c700c50809a3d4d8a506f4f797
Cleanup if early return from opj_j2k_copy_default_tcp_and_create_tcd().

The opj_j2k_copy_default_tcp_and_create_tcp() function memcpy's a top-level
struct, and then replaces pointers to memory owned by the original struct
with new blocks of memory. Unfortunately, an early return can leave the
copy with pointers to memory it doesn't own, which causes problems when
cleaning up the partially-initialized struct.

The referenced bug is triggered when we get a return at original
line 7969 or 7385 due to OOM.

Moral of the story: creating a "copy constructor" equivalent
based on memcpy() instead of copying field by field for structs
containing pointers is usually a bad idea.

BUG=486538
R=jun_fang@foxitsoftware.com

Review URL: https://codereview.chromium.org/1138033007
core/src/fxcodec/fx_libopenjpeg/libopenjpeg20/j2k.c